ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Exploit code threatening Windows PCs

Joris Evers CNET News.com

Published: 26 Jul 2006 09:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two new pieces of computer code that could spawn attacks on Microsoft Windows PCs have been released onto the Internet, security companies have warned.

The first exploit code takes advantage of a "critical" flaw in the Windows Dynamic Host Configuration Protocol, or DHCP, client, according to a customer alert sent out by the French Security Incident Response Team on Monday. Microsoft released a fix on 11 July for the problem, Symantec said in its own advisory for subscribers.

An attacker could gain full control over an unpatched Windows computer using the exploit, Symantec said.

Microsoft tackled the problem in security bulletin MS06-036, and people who have applied that update are protected, a representative for the software maker said.

The second, proof-of-concept code targets a security hole in a Windows component called "mailslot", which Microsoft patched in bulletin MS06-035, Symantec and FRSIRT said. However, Microsoft said it believes the code takes advantage of a new flaw.

"Proof-of-concept code was published on the Internet for a variant of the vulnerabilities addressed by Microsoft security update MS06-035," the representative for the software maker said. The company is monitoring this situation and may issue another patch, to fix the variant, the representative added.

Security experts pointed to the "mailslot" vulnerability as the most risky in Microsoft's July patch bunch. It could be used to spread a worm, they warned. However, the proof-of-concept code released over the weekend does not have as severe an effect; all it can do is crash a computer, Symantec said.

Microsoft said it is not aware of any actual attacks that use either of the two exploit-code samples, the representative said.

The company issued seven security bulletins with fixes for 18 flaws earlier this month. At least two of the vulnerabilities were already being exploited in attacks prior to the patches being released, security company iDefense has said. Also, soon after the monthly Patch Tuesday bulletins were released, miscreants launched attacks that exploit a new PowerPoint flaw.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
119 out of 200 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Head of Sales and Customer Relations

Manage the development of sales compensation plans and targets for the team, with support from Finance and Human Develop major areas of focus and key ...

MDX and CUBE experts,Get into the exciting world of Investment Banking

Seeking an intelligent and experienced Business Intelligence consultant to work on exciting projects, developing reports to advise and improve the ...

Technical Team leader ITIL Prince II - Oxfordshire

We are currently seeking an established people manager preferably from a technical background to lead and develop the team of senior ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment