Advertisement
Promo

Security threats Toolkit

Another security bug for Microsoft?

Patrick Gray ZDNet Australia

Published: 15 Oct 2003 10:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The security research community is divided over the seriousness of the latest bug in Microsoft's Windows operating system.

The latest glitch is in Window's DCOM code -- the same component of Windows targeted by the Blaster and Nachi worms in August -- but researchers are at this stage reluctant to call the flaw a full-blown exploitable vulnerability.

One Russian security researcher, known as Zaraza, posted a warning to the SecurityFocus bugtraq mailing list on Saturday. "Windows XP SP1 with all security fixes installed [is] still vulnerable to [a] variant of the same bug.... For a while only [the] DoS exploit [has existed], but code execution is probably possible," his post read.

A day later, US-based security company VigilantMinds released its own advisory. "VigilantMinds has validated that hosts running fully patched versions of the following Microsoft operating systems remain subject to denial of service attacks and possible remote exploitation," it read.

It was a vulnerability in Microsoft's DCOM code that was used as the basis for the creation of the devastating Blaster worm. Unlike an email-based worm, Blaster was a network-based worm that spread by automatically exploiting vulnerabilities on vulnerable systems. It is estimated Blaster infected between 300,000 and well over one million systems.

However US-based Internet Security Systems has today claimed prior analysis has been incorrect -- the issue is a newly discovered DCOM bug, not a variation on the previous one. "This vulnerability has been reported by various sources as a new exploit vector against the vulnerability disclosed in [Microsoft security bulletin] MS03-039. This assessment is incorrect," a statement issued by the company read.

According to the company's research team, which calls itself X-Force, it is unlikely the bug can be exploited by attackers to gain access to a vulnerable system. "X-Force has not demonstrated that this vulnerability can be used to execute arbitrary code or to compromise a vulnerable system. Significant barriers exist which may prevent reliable exploitation outside of controlled lab conditions," the statement read.

SecurityFocus have published workaround information that can be used to mitigate the bug until more information comes to hand.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
63 out of 94 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters