This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Ms Fesses Up To 19 Vulnerabilities...

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
February 08, 2005
"Microsoft Tuesday released its largest group of security patches in nearly a year as it posted 12 security bulletins encompassing 19 vulnerabilities, 14 of which it marked "Critical," its highest warning. Among them is a vulnerability that will likely lead to the biggest, baddest worm in since mid-2003, said Mike Murray, the director of research at vulnerability management vendor nCircle. "There's a clear 'winner' here," said Murray. " MS05-011 fixes a vulnerability in SMB (Server Message Block), which is running on every version of Microsoft's operating systems that a corporation might be using. And it's exploitable remotely, so it doesn't rely on an e-mail or getting someone to a Web site. All the attacker has to do is send a properly-formatted packet and he'll break in. "It's been a while since we've seen a vulnerability this widespread. This could easily lead to the biggest exploit in over a year," said Murray. "I'd put this in the same class as the vulnerability that led to (2003's) MSBlast. It's serious"…

The eight bulletins and 14 vulnerabilities marked Critical could all be used by attackers to execute code remotely – usually only after the user did something, such as visit a malicious Web site or click on a link within an e-mail – or create a buffer overflow that could then be used to gain control of a machine…"Every machine that has ports 139 and 445 open is at risk, and those ports are open on every standard Window box," he said. "Every Windows box is vulnerable"…His advice? Patch fast. "I think someone will break (this vulnerability) in the next couple of days, and we'll see a wormable exploit within a week"…"

:blink: >>> WindowsUpdate<<< :unsure: