Technology content trusted by users in Australia and around the world.
4,963 Articles | 29,980 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

AU EditionYou are located: Home > All News > News > Microsoft's latest patches hide serious threat

Microsoft's latest patches hide serious threat

By: (more) | Posted: Jan 14, 2009 7:32 pm

Three new bugs found in the way Windows handles SMB has raised the red flag for a number of security experts.

 

Although these bug have been patched by Microsoft people are concerned that these patches will not be put into place quickly enough to prevent their use.

 

The exploits can allow for remote execution and DoS attacks on the server by utilizing NetBIOS.

 

Read more here.

 

Microsoft's latest patches hide serious threat

Despite the seemingly light fare, experts say that IT should not be lackadaisical in applying the patch. An attacker does not need to steal any passwords in order to take over a machine or perform a denial-of-service (DoS) attack. Two of the vulnerabilities covered can lead to remote code execution while the third can lead to the DoS attack.

 

"In today's bulletin, the attacker does not require any credentials," says Amol Sarwate, manager of the vulnerabilities research lab at Qualys. "The vulnerable SMB ports are almost always guaranteed to be open for Windows to function properly so I would say this one is pretty serious."
And given the fact that the vulnerability is present on the Windows Server OS, there is no user intervention that has to occur before machines can be hacked. Just the mere presence of the server on the network makes it vulnerable.

 

The patch is listed "critical" on Windows 2000, XP and 2003 because NetBios is turned on be default, but only moderate on Vista and Windows Server 2008 where NetBios is off by default.

 

Related Tags



Further Reading: Read and find more news at our news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: Western Digital Scorpio Blue (WD5000LPVT) 500GB HDD Review
  • Upcoming Content: Scythe Mugen 4 Tower CPU Cooler Review
  • Upcoming Content: NZXT Grid 10 Port Fan Hub Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Star Trek: The Next Generation - Season Three (1989) Blu-ray Review
  • Upcoming Content: The Hobbit: An Unexpected Journey (2012) Blu-ray Movie Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: ADATA DashDrive Elite UE700 USB 3.0 Flash Drive Review
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Tech News Posts

View More News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Press Releases

View More Press Releases