Welcome | Sign In
TechNewsWorld.com
Exploits & Vulnerabilities

Microsoft Stomps Beastly Server Bugs

Print Version
E-Mail Article
Reprints
Microsoft Stomps Beastly Server Bugs

For its latest regular Patch Tuesday booster shot, Microsoft snuffed out vulnerabilities surrounding its Server Messenger Block Protocol. The vulnerabilities allowed hackers to bust into unpatched computers and do what they please -- create accounts, install software under the radar, etc.


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

Microsoft (Nasdaq: MSFT) issued a critical software update Tuesday, plugging three vulnerabilities in all versions of its Windows operating system. The three flaws, two of which were reported privately and the third of which was publicly disclosed, deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with a hole in the Microsoft Server Message Block (SMB) Protocol.

The vulnerabilities could enable an attacker who successfully exploits them to install programs; view, change or delete data; or create new accounts with full user rights. The security update addresses the flaws by validating the fields inside the SMB packets, according to Microsoft.

The software maker rated two of the security holes -- CVE-2008-4834 and CVE-2008-4835 -- as critical in Windows 2000, Windows XP and Windows Server 2003. The third flaw -- CVE-2008-4114, which also affects those OSes -- was given a moderate rating. The same vulnerabilities in Windows Vista and Windows Server 2008 were given a moderate rating by Microsoft.

The flaws are serious, insofar as exploits could lead to remote code execution and thereby to hackers controlling an affected computer, said Richard Wang, U.S. SophosLabs manager.

"However, we have not yet seen any malicious software taking advantage of this vulnerability," he told TechNewsWorld.

Critical Situation

The first two flaws concern unauthenticated remote code execution vulnerabilities, which exist in the way that Microsoft SMB Protocol handles specially crafted SMB packets. Efforts by hackers to exploit the flaws would not require authentication, thereby allowing attackers to exploit the vulnerabilities by sending a specially crafted network message to a computer running the Server service. Most attempts to exploit the security hole would result in a system denial of service condition; however, remote code execution is possible, at least theoretically, Microsoft said.

"CVE-2008-4834 and CVE-2008-4835 both allow remote code execution, meaning that a computer that is connected to the Internet is at risk. A remote attacker can install and execute programs, compromise the confidentiality, integrity or availability of sensitive data, and create administrator accounts," Chris Rodriguez, an analyst at Frost & Sullivan, told TechNewsWorld.

The remaining problem rests with a denial of service vulnerability that exists in the way that Microsoft SMB Protocol software handles specially crafted SMB packets. As with the other two flaws, an attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message to a computer running the service. Unlike the other vulnerabilities addressed in the patch, if an attacker successfully exploits the flaw, it could cause the user's computer to stop responding and restart.

Get the Shot

Microsoft recommends that Windows users install the security update immediately.

If a system is left unpatched, "it is possible hackers will be able to exploit this vulnerability to break into networks and install their own programs," Wang noted.

While no exploits have been detected that take advantage of these vulnerabilities, according to Rodriguez, businesses should be on guard.

"Organizations must vigilantly watch firewall configurations and close unnecessary ports on their computers," he pointed out.


Print Version E-Mail Article Reprints More by Walaika Haskins


More by Walaika Haskins

ZeeVee's Zinc Browser Gets Web TV Right
April 29, 2009
The Zinc Browser from ZeeVee updates the old Zviewer with tighter navigation and better catalog options. The finished application offers a great way to find TV shows and movies anywhere on the Web, regardless of whether they're hosted by Hulu, CBS, Netflix, Amazon's on-demand service or others.
Game Sales Sputter, 'GTA' Fails to Steal the Show
April 23, 2009
It may appear as though the video game industry is beginning to join the economy at large in its slump, as March numbers from NPD were less than encouraging. However, a year-over-year perspective is difficult due to the timing of game releases and holidays. Meanwhile, Take-Two hasn't seen much success in introducing its violent "GTA" series to the Nintendo DS.
Can Microsoft Win the Online Game?
April 16, 2009
Now that the major video game consoles have been on the market for two and a half years -- or more -- hardware sales have slowed considerably. Online services, however, still have room to grow. InStat says subscriber bases will take off in the coming years, and Microsoft's Xbox platform may come out the big winner.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network