Hackers find way to exploit latest Windows vulnerability
The code exploits security flaws acknowledged last week by Microsoft
September 17, 2003 12:00 PM ETIDG News Service -
A security company said yesterday that it found an example of working computer source code that exploits the latest critical security hole disclosed by Microsoft Corp.
Counterpane Internet Security Inc. in Cupertino, Calif., said it found and tested the source code, which it claimed exploits Microsoft operating systems that have one of three security flaws in the Microsoft Distributed Component Object Model (DCOM) component of Windows.
The development of a working exploit is a crucial step toward the creation of an Internet worm or virus that can infect large numbers of vulnerable Windows systems, raising the stakes for companies and home users who haven't downloaded and installed the Microsoft-supplied software patch, according to Bruce Schneier, chief technology officer at Counterpane.
Microsoft last week revealed the new DCOM security holes in a bulletin, MS03-039. The company said the holes are very similar to an earlier DCOM vulnerability that was exploited by the W32.Blaster and W32.Welchia Internet worms last month.
Malicious hackers could exploit the latest vulnerability by creating a program to send improperly formatted remote procedure call messages to a vulnerable machine. Those messages could cause a buffer overflow that would enable attackers to place and run their own computer code on the machine, without requiring the machine's owner to open an e-mail attachment or perform any other action, Microsoft said.
Counterpane tested the exploit code in its labs and found that the code opens an interface on the vulnerable system that would enable remote attackers to issue commands and take control of the system, according to Schneier.
This is the first known exploit of one of the vulnerabilities named in the MS03-039 bulletin, Schneier said, although no Counterpane customers have been attacked.
Counterpane researchers found the code on a public Web site frequented by virus writers but don't believe it has been released to the public yet, he said.
The exploit could easily be used in a worm or even swapped into the existing Blaster worm in place of the previous DCOM exploit code, Schneier said.
The appearance of exploit code means that companies should rush to patch vulnerable Windows machines while plugging ports targeted by the exploit, such as Ports 135, 139 and 445.
"Last week, the news was, 'It's coming, gotta get to [patching] quickly.' Now the news is, 'It's here. We've seen it. We have it. You've gotta get to [patching] now,'" Schneier said.
Because the exploit would be stopped by typical corporate firewall defenses, companies should pay particular attention to employees who use laptops at home and on the road. Often, these users get infected when not connected to the corporate network, then spread the infection to other machines on the network when they return to their offices.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources


White Papers & Webcasts
Addressing Compliance Initiatives with Tripwire and the Center for Internet Security
Learn the basics about security benchmarks, and specifically how the security benchmarks developed by the Center for Internet Security (CIS) can help you...
Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....
Case Study: The Ritz London
Discover how the superior capabilities of Webroot E-mail Security SaaS allows user to focus on their principal tasks instead of wasting their time...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Case Study: Richmond Ambulance Authority (RAA)
In this case study, find out how Webroot Web Security SaaS delivers the proactive web security RAA needs....
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Subscribe to Computerworld
