
Patch or else, warns Microsoft
By Joris Evers
Published: 27 June 2006 08:45 BST
Computer code that exploits a "critical" vulnerability in Windows has been released on the internet, prompting Microsoft to issue a security advisory.
The attack code takes advantage of a flawed Windows routing and remote access component for which Microsoft released a patch two weeks ago, the company said in its advisory published late on Friday. The company is not aware of any actual cyber attacks that use the exploit code, it said.
Microsoft said: "An attacker who successfully exploited this vulnerability could take complete control of the affected system."
It urges users to apply the fix delivered with security bulletin MS06-025, which will remove the vulnerability. "We have confirmed that the exploit code does not affect users who have installed the update," Microsoft said.
However, the MS06-025 fix can interfere with a certain dial-up networking connections, Microsoft said last week. The company advised people who use dial-up scripting or terminal window features not to install the security update while it works on a revised patch. That revision is still in the works, a Microsoft representative said on Monday.
The MS06-025 update was one of a dozen security bulletins that Microsoft released two weeks ago. At least one patch came after the vulnerability it addressed had already been exploited in a cyber attack. Exploits for some other flaws have also been released, further increasing the urgency to patch.
Joris Evers writes for CNET News.com
Microsoft: Yes, there's a flaw in Windows wi-fi...
Microsoft issues flaw fixes for Outlook and Windows
Microsoft to hunt 'new species' of bugs
Microsoft gets ahead of itself with WMF patch
Windows flaw could hit enterprise systems
Windows flaw spawns flurry of attacks
Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...
Activities and tasks: - Provide support of the firewall hardware and software which manages e-mail, web browsing, VPN services and dial up services ...
Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Websphere IT ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...