By Walaika Haskins TechNewsWorld
01/14/09 2:47 PM PT
For its latest regular Patch Tuesday booster shot, Microsoft snuffed out vulnerabilities surrounding its Server Messenger Block Protocol. The vulnerabilities allowed hackers to bust into unpatched computers and do what they please -- create accounts, install software under the radar, etc.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Microsoft (Nasdaq: MSFT) issued a critical software update Tuesday, plugging three vulnerabilities in all versions of its Windows operating system. The three flaws, two of which were reported privately and the third of which was publicly disclosed, deal with a hole in the Microsoft Server Message Block (SMB) Protocol.
The vulnerabilities could enable an attacker who successfully exploits them to install programs; view, change or delete data; or create new accounts with full user rights. The security update addresses the flaws by validating the fields inside the SMB packets, according to Microsoft.
The software maker rated two of the security holes -- CVE-2008-4834 and CVE-2008-4835 -- as critical in Windows 2000, Windows XP and Windows Server 2003. The third flaw -- CVE-2008-4114, which also affects those OSes -- was given a moderate rating. The same vulnerabilities in Windows Vista and Windows Server 2008 were given a moderate rating by Microsoft.
The flaws are serious, insofar as exploits could lead to remote code execution and thereby to hackers controlling an affected computer, said Richard Wang, U.S. SophosLabs manager.
"However, we have not yet seen any malicious software taking advantage of this vulnerability," he told TechNewsWorld.
Critical Situation
The first two flaws concern unauthenticated remote code execution vulnerabilities, which exist in the way that Microsoft SMB Protocol handles specially crafted SMB packets. Efforts by hackers to exploit the flaws would not require authentication, thereby allowing attackers to exploit the vulnerabilities by sending a specially crafted network message to a computer running the Server service. Most attempts to exploit the security hole would result in a system denial of service condition; however, remote code execution is possible, at least theoretically, Microsoft said.
"CVE-2008-4834 and CVE-2008-4835 both allow remote code execution, meaning that a computer that is connected to the Internet is at risk. A remote attacker can install and execute programs, compromise the confidentiality, integrity or availability of sensitive data, and create administrator accounts," Chris Rodriguez, an analyst at Frost & Sullivan, told TechNewsWorld.
The remaining problem rests with a denial of service vulnerability that exists in the way that Microsoft SMB Protocol software handles specially crafted SMB packets. As with the other two flaws, an attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message to a computer running the service. Unlike the other vulnerabilities addressed in the patch, if an attacker successfully exploits the flaw, it could cause the user's computer to stop responding and restart.
Get the Shot
Microsoft recommends that Windows users install the security update immediately.
If a system is left unpatched, "it is possible hackers will be able to exploit this vulnerability to break into networks and install their own programs," Wang noted.
While no exploits have been detected that take advantage of these vulnerabilities, according to Rodriguez, businesses should be on guard.
"Organizations must vigilantly watch firewall configurations and close unnecessary ports on their computers," he pointed out.
Security Wonks List Coders' Top 25 Worst Flubs January 12, 2009
High-profile organizations including Microsoft, the NSA, the SANS Institute and Mitre have collectively issued a list of the top 25 most dangerous programming errors. Slip-ups on the part of software coders can result in costly thefts by hackers. The remedy: better education and more accountability.
Related Stories
OS X vs. Windows: A Tale of Two Security Strategies November 17, 2008
The days are gone when Mac OS X security could be taken for granted. As Apple has increased its share of the computer market, hackers have become more interested in developing exploits for its software vulnerabilities. Like Microsoft, Apple must issue security patches from time to time, but the two companies have very different distribution approaches for their security fixes.
Patch Tuesday Fixfest Plugs 6 Critical Windows Weak Spots August 13, 2008
The set of fixes Microsoft sent out for its latest Patch Tuesday was its biggest in two years. The update addressed 26 known vulnerabilities, including six flaws the company considers critical. Critical flaws often indicate vulnerabilities that could allow outside parties to take control of a computer remotely.
Microsoft to Give White Hats a Head Start on Patch Tuesdays August 05, 2008
Trusted security vendors will soon get to see Microsoft's Patch Tuesday fixes each month before the rest of the world does. The company's new Microsoft Active Protection Program is designed to let security makers head off hackers, some of which begin crafting malware the moment Patch Tuesday fixes are made public in an attempt to strike at known vulnerabilities before everyone has plugged their systems.
Related News Alerts
More by Walaika Haskins
ZeeVee's Zinc Browser Gets Web TV Right April 29, 2009
The Zinc Browser from ZeeVee updates the old Zviewer with tighter navigation and better catalog options. The finished application offers a great way to find TV shows and movies anywhere on the Web, regardless of whether they're hosted by Hulu, CBS, Netflix, Amazon's on-demand service or others.
Game Sales Sputter, 'GTA' Fails to Steal the Show April 23, 2009
It may appear as though the video game industry is beginning to join the economy at large in its slump, as March numbers from NPD were less than encouraging. However, a year-over-year perspective is difficult due to the timing of game releases and holidays. Meanwhile, Take-Two hasn't seen much success in introducing its violent "GTA" series to the Nintendo DS.
Can Microsoft Win the Online Game? April 16, 2009
Now that the major video game consoles have been on the market for two and a half years -- or more -- hardware sales have slowed considerably. Online services, however, still have room to grow. InStat says subscriber bases will take off in the coming years, and Microsoft's Xbox platform may come out the big winner.