It doesn’t happen often, but when it does it gets the attention of the security world. Microsoft on Thursday issued an out-of-band patch designated as critical for Windows XP and older versions, and important for Windows Vista.
MS08-67 resolves a vulnerability in the server service that affects all currently supported versions of Windows. Because the vulnerability is potentially wormable on older versions of Windows, Microsoft is encouraging customers to test and deploy the update as soon as possible.
Microsoft discovered the vulnerability as part of its research into a limited series of targeted malware attacks against Windows XP systems. Researchers found attackers were using a new vulnerability that was potentially wormable. The company planned a Webcast on Friday to discuss the release.
Symantec tracked the issue as BugTraq ID 31874. The weakness allows an attacker to take complete control of a vulnerable system. While Symantec isn’t reporting a widespread exploitation of this issue, there have been reports of a certain file, n2.exe, being downloaded on compromised computers. According to the security firm, this file copies another piece of malicious code onto the compromised computer.
Holding Out Hope
This advisory has all the makings of a worm, according to Tyler Reguly, a security engineer for nCircle. “The difference between this and slammer or code red, or at least I hope it’s a difference, is that hopefully there aren’t too many Internet-facing machines listening on ports 139 and 445,” he said. “If it is facing the Internet, that means that not even a simple home router is used, and that thought scares me.”
Reguly could see this used by an employee inside a company. For example, if a company’s internal security isn’t adequate, a disgruntled employee with the proper skill set could take advantage of the vulnerability.
Security researchers are warning IT administrators to keep in mind…