This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

W2k 0-day Exploit - False Alarm (?)

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700028
May 25, 2006
"Symantec warned its enterprise customers Thursday that an unpatched vulnerability in Windows 2000's file sharing protocol has surfaced, with details of an exploit expected to show next month. According to the Cupertino, Calif. company's alert, an exploit for the zero-day bug in Windows 2000's SMB (Server Message Block) protocol has been created by Immunity Security*, the makers of the CANVAS exploit-creation platform. By Immunity researcher Dave Aitel's account, the exploit leverages a flaw in the operating system's kernel that can be triggered through SMB, and will give an attacker full access to the PC. Aitel claimed Immunity will make the exploit public in June. "Immunity is considered to be a reliable source and we are of the opinion that this information should be treated as fact," read Symantec's warning. "An official security update from Microsoft will likely not be in development until after June when the information is released." Until then, Symantec recommended that companies restrict SMB services to trusted hosts; if that's not possible, companies should consider upgrading to a newer version of Windows. Windows 2000 was last patched against an SMB vulnerability in June 2005 (MS05-027). Although Windows 2000 has been in its last lifespan stage since June 2005 – called "Extended Support" by Microsoft – the Redmond, Wash. developer still patches bugs in the OS during its monthly security updates."
* http://www.immunitysec.com/

EDIT/ADD:
- http://www.sarc.com/
"ThreatCon Level is 2
…Immunity has released to their exclusive Partners Program an exploit for an unpatched remote ring-0 (kernel-level) code-execution vulnerability in Microsoft Windows 2000. Reportedly, this will be released to the public in the June update to CANVAS. This vulnerability is apparently leveraged through the SMB services; administrators should restrict SMB access until an official update is available."

:ph34r:
FYI…

UPDATE: Windows 2000 Bug Alert False Alarm
- http://www.techweb.com/wire/security/188500396
May 25, 2006 (8:31 PM EDT)
"A vulnerability in Windows 2000's file sharing protocol that Symantec rang the alarm on Thursday morning is actually not a new bug, but is a flaw patched more than a year ago, Microsoft claimed later in the day. Early Thursday, Symantec warned its enterprise customers of a coming exploit of a "zero-day," or unpatched, vulnerability in Windows 2000's SMB (Server Message Block) protocol. Symantec based its warning on a posting to the Dailydave security mailing list, where Immunity Security, the makers of the CANVAS exploit-creation platform, said that it would release details of the exploit next month. "Immunity is considered to be a reliable source and we are of the opinion that this information should be treated as fact," read Symantec's warning.
Within hours, Microsoft countered Symantec's alert with a blog entry from the Microsoft Security Response Center (MSRC) team*. "We've investigated this claim and found the vulnerability being discussed is fixed by MS05-011, a security update released almost 16 months ago," wrote Stephen Toulouse, a MSRC program manager. "What is new is that someone reportedly has found a different way to exploit the vulnerability. But if you have the update, you're protected," added Toulouse. Windows 2000 was been patched several times against SMB bugs, including the February 2005 fix of MS05-011 and another in June of that year. Symantec's gaffe was its second embarrassment of the day. Also on Thursday, eEye Digital Security warned that Symantec's Anti-Virus Corporate Edition 10.0, as well as some of its consumer-grade anti-virus software, could be compromised remotely by a worm without any user interaction."

* http://blogs.technet.com/msrc/archive/2006/05/25/430278.aspx
May 25, 2006 10:59 PM

:(