Hackers find way to exploit latest Windows vulnerability
The code exploits security flaws acknowledged last week by Microsoft
September 17, 2003 12:00 PM ETIDG News Service -
A security company said yesterday that it found an example of working computer source code that exploits the latest critical security hole disclosed by Microsoft Corp.
Counterpane Internet Security Inc. in Cupertino, Calif., said it found and tested the source code, which it claimed exploits Microsoft operating systems that have one of three security flaws in the Microsoft Distributed Component Object Model (DCOM) component of Windows.
The development of a working exploit is a crucial step toward the creation of an Internet worm or virus that can infect large numbers of vulnerable Windows systems, raising the stakes for companies and home users who haven't downloaded and installed the Microsoft-supplied software patch, according to Bruce Schneier, chief technology officer at Counterpane.
Microsoft last week revealed the new DCOM security holes in a bulletin, MS03-039. The company said the holes are very similar to an earlier DCOM vulnerability that was exploited by the W32.Blaster and W32.Welchia Internet worms last month.
Malicious hackers could exploit the latest vulnerability by creating a program to send improperly formatted remote procedure call messages to a vulnerable machine. Those messages could cause a buffer overflow that would enable attackers to place and run their own computer code on the machine, without requiring the machine's owner to open an e-mail attachment or perform any other action, Microsoft said.
Counterpane tested the exploit code in its labs and found that the code opens an interface on the vulnerable system that would enable remote attackers to issue commands and take control of the system, according to Schneier.
This is the first known exploit of one of the vulnerabilities named in the MS03-039 bulletin, Schneier said, although no Counterpane customers have been attacked.
Counterpane researchers found the code on a public Web site frequented by virus writers but don't believe it has been released to the public yet, he said.
The exploit could easily be used in a worm or even swapped into the existing Blaster worm in place of the previous DCOM exploit code, Schneier said.
The appearance of exploit code means that companies should rush to patch vulnerable Windows machines while plugging ports targeted by the exploit, such as Ports 135, 139 and 445.
"Last week, the news was, 'It's coming, gotta get to [patching] quickly.' Now the news is, 'It's here. We've seen it. We have it. You've gotta get to [patching] now,'" Schneier said.
Because the exploit would be stopped by typical corporate firewall defenses, companies should pay particular attention to employees who use laptops at home and on the road. Often, these users get infected when not connected to the corporate network, then spread the infection to other machines on the network when they return to their offices.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
