Microsoft rushes to patch Windows vulnerability, hackers rush to exploit it

Home IT

Microsoft might have rushed out an emergency critical patch for Windows, out of the update cycle and in order to stop the bleeding from a privately reported vulnerability. But has it been enough to prevent a hacker spread infection getting into the open Windows wound?

As we reported on Saturday Microsoft has taken the most unusual step of issuing a critical Windows security patch on a Thursday. The last time this happened was way back in April 2007 in fact.

The emergency OS sticking plaster was required, it would seem, because of a vulnerability that had been reported privately and impacted upon the Server service for all versions of Windows from 2000 onwards.

That said it was Windows 200, XP and Server 2003 that would be most vulnerable to the remote code execution attacks if they were in receipt of the correctly crafted and malicious RPC request that could enable the running or arbitrary code without authentication.

Users of Windows Vista and Server 2008 do not escape either, as Microsoft has the patch tagged as 'important' even for them.

Unfortunately, it may be a little too late for many people. Especially those users of the older Windows systems who do not have automatic updates activated. A worm called Gimmiv has already been detected - with sample code posted online to help others exploit the security hole.

Microsoft had, one has to assume, already seen other exploits in the wild or it would not have take the emergency patching action in the first place. Unfortunately, the very act of releasing the patch in this way has alerted malicious idiots to the fact the vulnerability exists.

Since the patch announcement there has been a 25 percent increase in network scanning activity looking for this specific vulnerability. With the release of the Gimmiv source code, expect a flurry of password stealing attacks in the coming days and weeks.

It surely is just a matter of time before that code is converted into some ready made tool for the script kiddie hackers to use...

Please enable JavaScript in your browser to post your comment!

SPONSORED PRESS RELEASES

Independent Research Shows High Customer Satisfaction for NetSuite
NetSuite Inc. (NYSE: N), a leading vendor of cloud computing business management software suites, today announced that technology advisory firm Nucleus Research has completed an independent survey of NetSuite customers and concluded that NetSuite customers are highly satisfied, l...

Featured IT jobs

Senior Software consultant responsible for providing support on a unique enterprise level software solution for various customers, Melbourne based!
Skills Tags:   IT  ITIL  Linux  Management  RFP  Unix
This financial client has an excellent opportunity for an experienced Database Developer. SQL 2005 Some Schema design + SSIS & SSRS - 80k+super
Skills Tags:   Design  Development  SQL  SQL Server
Massive Hyperion Project requires a Hyperion Planning Architect / Lead Developer - drive home a huge Hyperion solution.
Skills Tags:   Architect  Design  Development  Hyperion
OBIEE Consultant to work on a very large greenfield OBIEE implementation to date to work end-to-end with excellent modelling & BI Server skills
Skills Tags:   Business Intelligence  Cognos  Hyperion  Informatica  Oracle  SQL

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases