
Attackers hoping to catch-out the unpatched?
By Joris Evers
Published: 2 December 2005 08:25 GMT
Two new pieces of computer code that could be used in cyber attacks on Windows users were posted on the web on Wednesday and Thursday.
The exploit posted on Thursday is another that could allow a remote attacker to gain complete control over a vulnerable computer. The code takes advantage of a flaw in a Windows component for transaction processing, called the Microsoft Distributed Transaction Coordinator. Microsoft addressed the flaw in security bulletin MS05-051 in October.
The attack code published on Wednesday is another that exploits a flaw in the way Windows handles certain graphics files and could cause a vulnerable system to crash. Microsoft provided a patch for the flaw in November with security bulletin MS05-053 and warned the vulnerability could create an opening for spyware and Trojan attacks.
Including these last two, a total of four exploits have been released for the same two Windows flaws since Sunday, according to the French Security Incident Response Team, a security research company.
David Marcus, security research and communications manager at McAfee, said: "It is reasonable to assume as we have seen so much proof-of-concept code distributed for these vulnerabilities that we will eventually see some class of attack."
While availability of attack code could provide cyber criminals with ammunition, patches and security software should shield Windows users, said Steve Manzuik, security product manager at eEye Digital Security.
Manzuik said: "I am sure some will try and use the exploits but the reality is there are patches for these issues and almost every security vendor would have by now added signatures to protect against this stuff."
Michael Sutton, director at security intelligence company iDefense, a part of VeriSign, agreed. "These vulnerabilities were patched, so fortunately clients have had weeks to patch," he said.
Microsoft is not aware of any attacks that use the latest exploits. However, the company warned this week of an attack that uses a yet-unpatched flaw in Internet Explorer. At least one exploit for that vulnerability has also been publicly released in the past two weeks.
Manzuik said: "That's the biggest threat out there, the Microsoft Internet Explorer vulnerability which has no patch. Currently there are exploits on the web for this that are not that malicious but it wouldn't be too hard for someone to take this and make it malicious."
Sutton also warned computer users to be on guard for exploitation of the unpatched bug. "The one to pay attention to is the vulnerability that remains unpatched. Microsoft has released an advisory for this but no patch yet," he said. Microsoft may issue a fix outside of its monthly patching cycle for this problem, Sutton said.
Microsoft's next monthly patch release is scheduled for 13 December.
Joris Evers writes for CNET News.com
You will conduct regular penetration tests using a variety of manual methods and specialist tools to find vulnerabilities and exploits and fix them. ...
These next-generation threats attack on multiple levels of the network infrastructure. CompanyMcAfee creates best-of-breed computer security ...
Core responsibilities: * Oversee security management and vulnerability program, * Ensure audit logs are monitored daily, * Conduct security awareness ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy