On CBSSports.com: Mike Tyson's daughter dies in accident
BNET Business Network:
BNET
TechRepublic
ZDNet

By Alorie Gilbert
Posted on ZDNet News: Jun 24, 2005 11:42:00 PM

The risk of an attack related to a flaw in Microsoft Outlook Express climbed this week, after underground hacking sites began circulating sample code for exploiting it.

The exploit, which the French Security Incident Response Team drew attention to on Monday, is designed to take complete control of PCs with certain versions of the Outlook Express e-mail program installed on them, when users visit newsgroups controlled by the hackers.

But security experts said the risk of a widespread attack is low, because people must visit the malicious newsgroups for an attack to work. In addition, the exploit code that's in circulation has some glitches, said Michael Sutton, a lab director at security company iDefense.

"It requires a reasonable amount of user intervention, which lowers the overall risk," Sutton said.

Nonetheless, iDefense urges people with vulnerable machines to install the patch Microsoft released last week to fix the flaw. The problem stems from a component of Outlook's newsreader program called Network News Transfer Protocol. The result of an attack could be serious.

"An attacker could install programs; view, change or delete data; or create new accounts with full user rights," Microsoft warned in a security bulletin for the patch last week. The company rated the vulnerability "important," which falls second to "critical" in its rating scale.

A Microsoft representative said the company is aware of the exploit code but is unaware of active attacks that have utilized it. Microsoft is monitoring the situation and is urging customers to apply its patch, the representative said. The company also directed people to report any attacks to Microsoft and the FBI.

The vulnerability has been found in several versions of Outlook Express, including releases 5.5 and 6.0 for Windows 2000, XP and Server 2003 machines, according to Microsoft. People don't have to launch the Outlook Express program, however, in order to fall victim to an attack.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 46 Talkback(s)
At least you did not deny the Troll Status
You said:
"They use Outlook newsgroups for their online courses"

I agree with
"They are a national college, they use spam for their recruiting practices, suck millions off of students an... (Read the rest)
Posted by: Squawkbox Posted on: 06/27/05 You are currently: a Guest | | Terms of Use
This is scary...  Colonel_Panic | 06/24/05
Obviously .....  rick752 | 06/24/05
Indeed it is  crashoverride | 06/24/05
It's not OE specifically  IT Scion | 06/24/05
It's not OE, It's Windows  IT-sys | 06/24/05
While your last scentence is true  crashoverride | 06/24/05
Want to read something funny? I just...  Colonel_Panic | 06/25/05
I love butchering windoze too  crashoverride | 06/26/05
Want to learn something?  SiCu | 06/26/05
Re: Want to learn something?  Colonel_Panic | 06/26/05
It's not like people are using Windows  Boot_Agnostic | 06/27/05
Tell me AGAIN  CobraA1 | 06/24/05
Not MS this time ... well, sort of ...  ac2_z | 06/25/05
It's the programmers, Stu.  Marc Thibault | 06/25/05
I agree. I do have education.  Grayson Peddie | 06/25/05
Pull the plug  Otto_Delete | 06/25/05
I can mantain my Windows computer  Grayson Peddie | 06/25/05
You are correct  Otto_Delete | 06/25/05
I guess I'm not one of the 99.999% of home users  crashoverride | 06/25/05
security? we don need no stinkin security!  linuxoverwindows | 06/25/05
aaa, yes linux  crashoverride | 06/25/05
I can help educate you about the security.  Grayson Peddie | 06/25/05
Who needs Windows OneCare  crashoverride | 06/25/05
Then try installing...  Grayson Peddie | 06/26/05
I'm not a zealot yet  crashoverride | 06/26/05
Since no one else has asked.  Cardinal_Bill | 06/26/05
I can help educate you about the security.  Grayson Peddie | 06/25/05
Oh...sorry. Double post.  Grayson Peddie | 06/25/05
RE: I can help educate you about the security.  Linux User 147560 | 06/26/05
RE: I can help educate you about the security.  Linux User 147560 | 06/26/05
RE: I can help educate you about the security.  Linux User 147560 | 06/26/05
It took you three ...  ShadeTree | 06/27/05
I have to say you're right about home users  pesky_z | 06/25/05
true that.  linuxoverwindows | 06/25/05
Windows OneCare  Grayson Peddie | 06/25/05
or, try this:  linuxoverwindows | 06/25/05
Thanks, but not for me.  Grayson Peddie | 06/25/05
You are so naive Grayson...they "Don'tCare". Just more  Colonel_Panic | 06/25/05
Quite honestly if Microsucks can't  crashoverride | 06/26/05
But you said you are  Linux User 147560 | 06/26/05
Outhouse Exploit --->new name, same...  Colonel_Panic | 06/26/05
Remarkable Craftsmanship  michael_t | 06/26/05
Hackers Should Target University Of Phoenix  itanalyst | 06/27/05
Your bias is showing  Squawkbox | 06/27/05
How Is That Bias?  itanalyst | 06/27/05
At least you did not deny the Troll Status  Squawkbox | 06/27/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here