Microsoft issued two new security updates to fix three Windows vulnerabilities in the year’s first Patch Tuesday update. Microsoft rated one of the bugs — a TCP/IP vulnerability — critical.
The TCP/IP bug affects Windows XP, Windows Server 2003, and Windows Vista. This vulnerability does not require any user interaction to exploit and could potentially result in a remote compromise of the attacked computer. The other two flaws are rated important and moderate.
Ben Greenbaum, senior research manager of Symantec Security Response, said the TCP/IP vulnerability could be a significant issue, depending on the user’s firewall settings.
“This issue is compounded by the fact the user’s computer may automatically reboot upon a failed exploit attempt, giving the attacker multiple opportunities to compromise the computer,” he explained. “Users should utilize firewall best practices, such as blocking IGMP packets, so their computers will not be at risk.”
No User Interaction Required
The severity of the issue is underscored by the fact that no user interaction is required to exploit the vulnerability, said Amol Sarwate, manager of the Vulnerability Research Lab at Qualys.
“The user does not have to do anything — open an e-mail, browse a malicious Web site, or even be present at the machine,” Sarwate warned. “As long as the target machine is running, an attacker could send a maliciously crafted packet through IGMP, ICMP, or MLD protocols and execute any code of their choice and take control of the system.”
Some of the applications that could be compromised or serve as attack vectors include any live broadcast video or audio streams, such as IP-based teleconferencing or collaborative online environments, warned Don Leatham, director of business development at Lumension Security.
“Attackers may even be able to use live video feeds from security cameras or other ‘interactive’ video services,” Leatham said. “We suggest…