You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft 'critically' patches 'worm hole'

…couldn't wait until patch Tuesday

Tags: patch, vista, windows, microsoft

By Robert Vamosi

Published: 24 October 2008 08:54 GMT

On Thursday, Microsoft issued a rare out-of-cycle patch for a vulnerability in the Windows Server service that handles remote procedure calls (RPC) that allows programmers to run code either locally or remotely.

In issuing MS08-067, Microsoft warns "it is possible that this vulnerability could be used in the crafting of a wormable exploit". Entitled 'Vulnerability in Server Service Could Allow Remote Code Execution (958644)' the specific vulnerability has been assigned a National Vulnerability Database designation of CVE-2008-4250.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

Microsoft rates this patch as critical for Microsoft Windows 2000, Windows XP, Windows Server 2003, and important for Windows Vista and Windows Server 2008. It also affects versions of Windows 7 pre-beta in limited release. The patch replaces MS06-040.

Microsoft normally issues patches on the second Tuesday of each month, which has been deemed Patch Tuesday. But out-of-cycle patches are not without precedent. Recent examples include the Windows Animated Cursor Remote Code Execution Vulnerability (April 2007), a vulnerability in Vector Markup Language (September 2006), and a vulnerability in the Graphics Rendering Engine (January 2006).

Microsoft said there have been only limited and targeted attacks to date.

The company did say that a firewall should block network resources from attacks from outside the enterprise perimeter.

The patch is available via Microsoft Update or the individual bulletin for MS08-067.

Original article: Microsoft patches potential 'worm hole' from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Desktop Support / Windows Systems Administrator - London

Your core responsibilities will be to manage the desktip environment and provide support to a large user base locally and remotely. You will need to ...

Systems Engineering Analyst

You will also have good interpersonal and professional skills.As a consultant you will have a mixture of technical Microsoft skills including ...

Senior Microsoft Windows Server Engineer

Overall Purpose of Role:My client is seeking a Senior Microsoft Windows Server Engineer to work with our existing Windows Server team. Our company is ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: