ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Exploit code threatens older Windows

Joris Evers CNET News.com

Published: 18 Nov 2005 09:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Exploit code has been published that could take advantage of flaws in Windows XP Service Pack 1 and Windows 2000 Service Pack 4, according to a warning issued on Thursday by Microsoft.

Although the exploit code could be used to launch a denial-of-service (DoS) attack in machines running XP SP1 and Windows 2000 with all service pack versions, the threat is only moderately severe, said Stephen Manzuik, a product manager at security research company eEye Digital Security.

"On a scale of 10, it would be about a 4 or 5 on severity," said Manzuik. "All it will do is crash some machines and not crash others."

The exploit code could allow an attacker to launch a remote DoS attack on Windows 2000 machines using all service pack versions, but would require a user authentication on Windows XP SP1 computers, Manzuik said.

The exploit poses only a moderate risk because it requires a user to log on for Windows XP, and in the case of Windows 2000, the attacker would have to get remote access to the Remote Procedure Code (RPC) port. That port is often behind a firewall, making it difficult to penetrate remotely, Manzuik noted.

Microsoft has yet to develop a security patch for this exploit, but it recommended that users enable their firewalls and download security updates, according to its security advisory.

The exploit code was published by Winny Thomas of Nevis Labs in India, who reverse-engineered a patch Microsoft issued in October, according to a posting on FrSIRT's Web site. The patch, MS05-047, dealt with a plug-and-play feature in the Windows software.

"While working on an exploit for MS05-047, I came across a condition where a specially crafted request to upnp-getdevicelist would cause services.exe to consume memory to a point where the target machines virtual memory gets exhausted. This exploit is not similar to the MS05-047 exploit I published earlier," Thomas noted in his posting.

The October patch did not lead to the vulnerability in Windows, a Microsoft representative said, adding that Microsoft encourages people to "apply the MS05-047 update and all recent security updates released by Microsoft."

Microsoft, however, reiterated its concerns over security researchers who publish details on how to exploit vulnerabilities before the software vendor has had time to create a patch.

"Microsoft is concerned that this new report of a vulnerability in Windows 2000 SP4 and Windows XP SP1 was not disclosed responsibly, potentially putting computer users at risk," the company said. "We continue to encourage responsible disclosure of vulnerabilities."

Some security researchers, however, note that Microsoft has been known to take at least 200 days or more to issue a security patch, once the company has been notified of a problem.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 148 people found this useful



Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

DESKTOP SPECIALIST- Financial Traders- London City (40-45k)

Additional knowledge of energy trading applications, application packaging and imaging, and security patch management would be useful as well as ...

Environment Engineer

Other activities would include booking and scheduling rig usage, ensuring all Government Furnished Equipment remains traceable and ensuring currency ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

You should have experience working with Active Directory, Microsoft exchange, Windows Server 2003, Windows XP and Office 2000/2003. I am looking for ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.