Microsoft Patch Tuesday exploit surfaces

Exploit for critical vulnerability increases calls to patch

Tom Sanders in California

Malware authors have crafted an exploit that attacks a security vulnerability patched by Microsoft as part of last Tuesday's security update.

The attack uses a vulnerability that Microsoft described in security bulletin MS06-040. It describes a buffer overflow vulnerability in the Windows Server component, affecting Windows 2000, Windows XP and Windows Server 2003.

Advertisement

The exploit only works on systems running Windows 2000 or Windows XP without any service packs. Most Window XP systems run service pack 2.

Attackers can contact the affected component through TCP ports 139 and 445. Both ports are used for NetBIOS sessions including Windows File and Printer sharing.

The exploit prompted the US Department of Homeland Security to issue a press release urging users to apply Tuesday's patch.

Few security experts were surprised by the speed at which online criminals started exploiting the vulnerability.

Bojan Zdrnja with the SANS Internet Storm Center and a security researcher for the University of Auckland warned that the code will cause more widespread attacks as less sophisticated virus writers start creating copy-cat malware.

"It's just a matter of time when script kiddies will start using this, if they haven't already," said Zdrnja.

"We can expect that this exploit will soon be added to the attack arsenal of bots such as Sdbot and similar. In other words – patch!"

The MS06-040 exploit marks the first attack new following this week's Microsoft patch release.

The patch plugged 23 security vulnerabilities, 11 of which were actively being exploited at the time of the release.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation