Advertisement
Promo

Security threats Toolkit

Microsoft Host Integration Server flaw exploited

Robert Vamosi CNET News

Published: 17 Oct 2008 12:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

On Thursday, new code was posted on the internet that could exploit a flaw in unpatched Microsoft Host Integration Servers.

The exploit is part of Metasploit, a toolkit used by penetration testers and criminal hackers alike.

On Tuesday, Microsoft issued security bulletin MS08-059 to address the vulnerability detailed in CVE- 2008-3466.

In its patch bulletin, ranked as critical, Microsoft said: "This vulnerability could allow remote code execution if an attacker sent a specially crafted remote procedure call request to an affected system."

Read this

Q&A
Microsoft gears up for victory in the virtual battle

According to Microsoft's Zane Adam, the company will use its tried and tested methods to grab a much bigger share of the virtualisation market...

Read more +

"Customers who follow best practices and configure the systems network architecture remote procedure call (SNA RPC) service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights," Microsoft said.

Apparently Microsoft knew of the exploit. To help system administrators prioritise the patches, an 'exploitablity index' was included with the October 'Patch Tuesday' releases.

Microsoft gave MS08-059 a '1' for having "consistently functioning exploits".

Other index ratings include '2' for "inconsistently functioning exploits" (of moderate concern), and '3' for vulnerabilities that are "unlikely to produce functioning exploits" (of least concern).

Credit: Microsoft Host Integration Server flaw exploited from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

homer

lets show everyone that labour has compasion[whilst there counting the votes] running upto march/april 2010...http://tinyurl.co...nus very good nb gordon brown said today on our... More

Post a comment

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

Post a comment

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters