You are here: silicon.com > Software > Security Strategy

Security Strategy

New worry about MSBlast sequel

Get patching again

By Robert Lemos

Published: 24 October 2003 09:55 GMT

A program that exploits a software vulnerability Microsoft recently described could spell trouble for companies that haven't quickly patched their system, security experts said this week.

Released on a security mailing list earlier this week, the program takes advantage of a flaw in Microsoft's Messenger Service to cause Windows-based computers to crash. The vulnerability affects almost every current Microsoft Windows system, leaving security experts concerned that independent hackers will quickly find a way to take control of a large number of computers by exploiting the flaw.

"I think we are going to see a repeat of the [MSBlast worm]," said Vincent Weafer, senior director of Symantec's antivirus research centre, referring to the program that spread across the internet in August. The program used a similarly widespread Windows flaw to break through computers' security. "It took three weeks [for hackers] to figure out a working worm in that case."

Programs that illustrate how to take advantage of such holes are known as "exploit code" and are seemingly being developed faster, coming out soon after the first notification of a flaw, a recent study by Symantec found.

This isn't the first time the Windows Messenger feature has been the source of users' pain. Not to be confused with Microsoft's instant messaging services, the Messenger feature allows Windows applications to communicate and send data among themselves. The feature has already been exploited by some spammers to send messages directly to users' desktops.

The flaw that led to the MSBlast worm affected another Windows service, known as the distributed component object model (DCOM), which allows components of the operating system to communicate. The software is a fundamental piece of the operating system, so the flaw affected all versions of Windows.

Microsoft announced the latest flaw a week ago as one of several security problems it highlighted in its first monthly security update. At the time, the software giant said all the flaws could be exploited to create a worm. "All of the five critical [vulnerabilities] are, of course, critical, so that means they are wormable," Jeff Jones, senior director of Microsoft's security business unit, said last week.

On Monday, a researcher released source code to a security mailing list, showing how to crash a computer using the flaw. Because the issue affects so many computers, companies should patch the issue quickly, said Craig Schmugar, virus research engineer for Network Associates.

"The greater the number of vulnerable systems out there, the greater the concern," he said. "We definitely take the demo code seriously."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Symantec Security Consultant, Symantec Endpoint, SEE, Cisco, London

Symantec Security Consultant / Engineer (Symantec SEP, SEE) required urgently for pivotal role within an award winning IT security company who are ...

Security Consultant (Symantec SEP, SEE, SAV)

Security Consultant (Symantec SEP, SEE, SAV) Our client is an award winning single supplier of all IT security requirements, and are experts in ...

Business Systems Platform Support Engineer

Key accountabilities To manage the provision of Linux operating system to support the Business System community To provide technical support to the ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: