Microsoft
Microsoft

Hackers pounce on latest Microsoft flaw

Code already being developed for launch of next big worm

Iain Thomson

Hackers have moved quickly to exploit the critical flaw in Microsoft's Distributed Component Object Model (DCOM) Remote Procedure Call (RPC) interface.

Workable exploit code is now in circulation on hacking mailing lists. Earlier versions were ineffective but the latest code seems to be working.

Advertisement

Microsoft released a patch for the critical flaw on 16 July.

The vulnerability involves the RPC protocol, which deals with inter-computer communications. Microsoft warned that, under certain circumstances, the RPC might not properly check messages sent to the PC.

A malformed message could be routed through port 135 and used to run code on the infected PC. Windows Exchange Server 2003, XP, 2000 and NT 4 are all affected.

"This is a big one," said Gunter Ollmann, EMEA manager at X-Force Security Assessment Services.

"Various versions of exploit code are now available and doing the rounds for the vulnerability. ISS is on AlertCon 3 at the moment, and may be going up to level 4, our highest level.

"There is already talk in both the underground and other security forums of worm development using this vulnerability."

Initial reports from mailing lists suggest that, while the exploit code may run, it is still easily detectable.

Once exploitation is complete RPC/DCOM functions fail completely, affecting functions like drag and drop or using the clipboard. This makes any attempt at hacking highly visible.

"It's certainly a danger in terms of worm development," said Graham Titterington, senior analyst at Ovum.

"This is a fundamental flaw in the architecture and many people won't get round to patching it; that's just the way the world works."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Blaster

Blaster worm starts European campaign

Lovesan/Blaster on the move following US infections

Virsu

US government warns on Microsoft bug

Second alert in six days as exploit code threatens millions of PCs

Microsoft warns on trio of new flaws

Patch available for critical flaw in all current versions of Windows

Flaw hits NT 4, Windows 2000 and XP

'Important' RPC flaw cannot be patched on NT 4, warns Microsoft

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

HTC Hero

Video: HTC Hero launch

Handset maker unveils its latest Android-based smartphone

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

firefox logo

In Pictures: Firefox 3.5

Screenshots from Mozilla's latest Firefox web browser

BT

BT scraps Phorm rollout

Telco claims to be too tight on resources to support...

Nokia

Nokia denies Android smartphone rumours

Mobile phone giant insists it will stick with Symbian

Second Life

Second Life seeks to mix the real and virtual worlds

Linden Lab unveils plans to integrate with social networks and...

Primary Navigation