ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Malicious code targets critical Windows flaw

Joris Evers CNET News.com

Published: 27 Jun 2006 10:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer code that exploits a "critical" vulnerability in Windows has been released on the Internet, prompting Microsoft to issue a security advisory.

The attack code takes advantage of a flawed Windows routing and remote-access component for which Microsoft released a patch two weeks ago, the company said in its advisory published late Friday. The company is not aware of any cyberattacks that use the exploit code, it said.

"An attacker who successfully exploited this vulnerability could take complete control of the affected system," Microsoft said.

Microsoft urges users to apply the fix delivered with security bulletin MS06-025, which will remove the vulnerability. "We have confirmed that the exploit code does not affect users who have installed the update," Microsoft said.

However, the MS06-025 fix can interfere with certain dial-up networking connections, Microsoft said last week. The company advised people who use dial-up scripting or terminal window features not to install the security update while it works on a revised patch. That revision is still in the works, a Microsoft representative said on Monday.

The MS06-025 update was one of a dozen security bulletins that Microsoft released two weeks ago. At least one patch came after the vulnerability it addressed had already been exploited in a cyberattack. Exploits for some other flaws have also been released, further increasing the urgency to patch.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
85 out of 150 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Senior Tester - Essex - 40k - Financial Markets (FIX)

My client based in Essex is a leading player in the FIX Market and are exclusively a Microsoft Development House using the latest tools such as ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Websphere IT Specialist / Architect

Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Websphere IT ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.