Microsoft issues emergency patch

Out-of-cycle update fixes serious, wormable flaw.

Microsoft has issued an emergency update to cover a serious vulnerability in the Windows Server service, breaking its usual monthly 'Patch Tuesday' cycle of security fixes.

Advertise on www.virusbtn.com

The flaw was considered serious enough to merit an urgent patch release, although Microsoft will only confirm having seen the usual 'limited, targeted' exploitation. The flaw was apparently uncovered by security researchers at Microsoft while investigating an extant trojan attack, and VB has already received several reports of such trojans taking advantage of the flaw in the Server service and file sharing.

With the nature of the flaw and the possibility of a specially targeted worm taking advantage of it to create a widespread outbreak, all users are being urged to patch as a matter of urgency. The updated October security bulletin from Microsoft is here, with blog entries from members of the security team here and from the Microsoft Malware Protection Center here. Alex Eckleberry at the Sunbelt blog compares the vulnerability and its potential for exploitation with the likes of W32/SQLSlammer and W32/CodeRed, here.

24 October 2008

Tags: microsoft, patch, patch tuesday, trojan, vulnerability, worm.    del.icio.us  digg this! digg this

0 comments

Comments are closed.

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Recruit Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
2 hours ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
6 hours ago


Virus Bulletin

In this month's magazine:
  • VB100 – Windows Vista Business Edition Service Pack 2
  • Apple pie order?
  • Anti-unpacker tricks – part eleven
  • Advanced exploit framework lab set-up
  • HTML structure-based proactive phishing detection
  • What’s the deal with sender authentication? Part 3
Virus Bulletin 08 2010
Subscribe now!
Virus Bulletin currently has 208,224 registered users.