Advertisement
Promo

Security threats Toolkit

Microsoft to fix zero-day SMB, IIS holes

Elinor Mills CNET News

Published: 09 Oct 2009 14:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Thursday said it will provide a fix next week for zero-day flaws in Microsoft Server Message Block and Internet Information Services that could allow an attacker to take control of a computer.

Those are just two of the 34 vulnerabilities addressed in 13 bulletins (eight of which are critical and five of which are rated important) that will be fixed during Patch Tuesday, according to a blog post on the announcement. The bulletins affect Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools and SQL Server, the advisory shows.

The Server Message Block (SMB) flaw was reported a month ago. At the time, Microsoft said it affected Vista, Windows Server 2008, and the "release candidate" version of Windows 7, but not the final version that was completed in July. Windows Server 2008 R2 is not vulnerable, and neither are the earlier Windows XP and Windows 2000 operating systems .

Microsoft, which previously released a temporary fix for the SMB hole, reported the Internet Information Services (IIS) flaw in the File Transfer Protocol in August. Its advisory says there have been limited attacks that use the IIS flaw exploit code, which was posted on the Milw0rm website, according to IDG News Service.

For the full story, see Microsoft to patch zero-day SMB, IIS holes at CNET News.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 7 people found this useful


Full Talkback thread

2 comments

  1. BUSY PATCH TUESDAY!! lumension
  2. Yup... CA

Company/Topic Alerts

Create a new alert from the list below:












Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters