Microsoft Patch Tuesday exploit surfaces

Exploit for critical vulnerability increases calls to patch

Written by Tom Sanders in California

Malware authors have crafted an exploit that attacks a security vulnerability patched by Microsoft as part of last Tuesday's security update.

The attack uses a vulnerability that Microsoft described in security bulletin MS06-040. It describes a buffer overflow vulnerability in the Windows Server component, affecting Windows 2000, Windows XP and Windows Server 2003.

Advertisement

The exploit only works on systems running Windows 2000 or Windows XP without any service packs. Most Window XP systems run service pack 2.

Attackers can contact the affected component through TCP ports 139 and 445. Both ports are used for NetBIOS sessions including Windows File and Printer sharing.

The exploit prompted the US Department of Homeland Security to issue a press release urging users to apply Tuesday's patch.

Few security experts were surprised by the speed at which online criminals started exploiting the vulnerability.

Bojan Zdrnja with the SANS Internet Storm Center and a security researcher for the University of Auckland warned that the code will cause more widespread attacks as less sophisticated virus writers start creating copy-cat malware.

"It's just a matter of time when script kiddies will start using this, if they haven't already," said Zdrnja.

"We can expect that this exploit will soon be added to the attack arsenal of bots such as Sdbot and similar. In other words – patch!"

The MS06-040 exploit marks the first attack new following this week's Microsoft patch release.

The patch plugged 23 security vulnerabilities, 11 of which were actively being exploited at the time of the release.

Tags:

Further reading

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Microsoft

Microsoft plans Silverlight 2.0 announcement

Web application tool revamp promised later today   More...

Stock prices

Security disclosures tip the stock market

Events such as Microsoft's Patch Tuesday could be used for...  More...

Blogs

Analyst predicts Web 2.0 fire sale

Prices for online apps could soon plummet, says Forrester   More...

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Primary Navigation