All the latest UK technology news, reviews and analysis

Microsoft warns of Windows zero-day flaw

by Shaun Nichols

18 Feb 2011

Comment: 1

  • Tweet this

Microsoft has warned of a recently disclosed vulnerability in the CIFS/SMB component of Windows affecting all supported versions of the operating system.

The company said that it first received word of the vulnerability earlier this week when a proof-of-concept sample was disclosed.

The exploit can be remotely activated and could cause a system crash and the infamous 'blue screen' error message.

The vulnerability is being classified by Microsoft as a 'critical' risk, but is not believed to allow remote code execution.

Microsoft researcher Matt Oh said in a posting to the Microsoft Malware Protection Center blog that certain parts of the vulnerable component could consistently be targeted, but causing remote code execution would be extremely difficult.

"Our conclusion is that the part of the string that the attacker can control will always end up inside the allocated buffer, and the part the attacker can't control is in the part that overflows the buffer," he said.

"Also, it is not possible to control the length of data to overwrite, so that it's always the same (and predictable) huge integer value."

Administrators can disable the Browser protocol to mitigate the risk of an attack. Microsoft did not say when a permanent fix will be released. The next scheduled patch is on 8 March.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

39%

0%

10%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.