On GameSpot: Next-gen DS, Xbox tech contracts set?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Alorie Gilbert
Posted on ZDNet News: Jun 24, 2005 11:42:00 PM

The risk of an attack related to a flaw in Microsoft Outlook Express climbed this week, after underground hacking sites began circulating sample code for exploiting it.

The exploit, which the French Security Incident Response Team drew attention to on Monday, is designed to take complete control of PCs with certain versions of the Outlook Express e-mail program installed on them, when users visit newsgroups controlled by the hackers.

But security experts said the risk of a widespread attack is low, because people must visit the malicious newsgroups for an attack to work. In addition, the exploit code that's in circulation has some glitches, said Michael Sutton, a lab director at security company iDefense.

"It requires a reasonable amount of user intervention, which lowers the overall risk," Sutton said.

Nonetheless, iDefense urges people with vulnerable machines to install the patch Microsoft released last week to fix the flaw. The problem stems from a component of Outlook's newsreader program called Network News Transfer Protocol. The result of an attack could be serious.

"An attacker could install programs; view, change or delete data; or create new accounts with full user rights," Microsoft warned in a security bulletin for the patch last week. The company rated the vulnerability "important," which falls second to "critical" in its rating scale.

A Microsoft representative said the company is aware of the exploit code but is unaware of active attacks that have utilized it. Microsoft is monitoring the situation and is urging customers to apply its patch, the representative said. The company also directed people to report any attacks to Microsoft and the FBI.

The vulnerability has been found in several versions of Outlook Express, including releases 5.5 and 6.0 for Windows 2000, XP and Server 2003 machines, according to Microsoft. People don't have to launch the Outlook Express program, however, in order to fall victim to an attack.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 46 Talkback(s)
At least you did not deny the Troll Status
You said:
"They use Outlook newsgroups for their online courses"

I agree with
"They are a national college, they use spam for their recruiting practices, suck millions off of students an... (Read the rest)
Posted by: Squawkbox Posted on: 06/27/05 You are currently: a Guest | | Terms of Use
This is scary...  Colonel_Panic | 06/24/05
Obviously .....  rick752 | 06/24/05
Indeed it is  crashoverride | 06/24/05
It's not OE specifically  IT Scion | 06/24/05
It's not OE, It's Windows  IT-sys | 06/24/05
While your last scentence is true  crashoverride | 06/24/05
Want to read something funny? I just...  Colonel_Panic | 06/25/05
I love butchering windoze too  crashoverride | 06/26/05
Want to learn something?  SiCu | 06/26/05
Re: Want to learn something?  Colonel_Panic | 06/26/05
It's not like people are using Windows  Boot_Agnostic | 06/27/05
Tell me AGAIN  CobraA1 | 06/24/05
Not MS this time ... well, sort of ...  ac2_z | 06/25/05
It's the programmers, Stu.  Marc Thibault | 06/25/05
I agree. I do have education.  Grayson Peddie | 06/25/05
Pull the plug  Otto_Delete | 06/25/05
I can mantain my Windows computer  Grayson Peddie | 06/25/05
You are correct  Otto_Delete | 06/25/05
I guess I'm not one of the 99.999% of home users  crashoverride | 06/25/05
security? we don need no stinkin security!  linuxoverwindows | 06/25/05
aaa, yes linux  crashoverride | 06/25/05
I can help educate you about the security.  Grayson Peddie | 06/25/05
Who needs Windows OneCare  crashoverride | 06/25/05
Then try installing...  Grayson Peddie | 06/26/05
I'm not a zealot yet  crashoverride | 06/26/05
Since no one else has asked.  Cardinal_Bill | 06/26/05
I can help educate you about the security.  Grayson Peddie | 06/25/05
Oh...sorry. Double post.  Grayson Peddie | 06/25/05
RE: I can help educate you about the security.  Linux User 147560 | 06/26/05
RE: I can help educate you about the security.  Linux User 147560 | 06/26/05
RE: I can help educate you about the security.  Linux User 147560 | 06/26/05
It took you three ...  ShadeTree | 06/27/05
I have to say you're right about home users  pesky_z | 06/25/05
true that.  linuxoverwindows | 06/25/05
Windows OneCare  Grayson Peddie | 06/25/05
or, try this:  linuxoverwindows | 06/25/05
Thanks, but not for me.  Grayson Peddie | 06/25/05
You are so naive Grayson...they "Don'tCare". Just more  Colonel_Panic | 06/25/05
Quite honestly if Microsucks can't  crashoverride | 06/26/05
But you said you are  Linux User 147560 | 06/26/05
new name, same...  Colonel_Panic | 06/26/05
Remarkable Craftsmanship  michael_t | 06/26/05
Hackers Should Target University Of Phoenix  itanalyst | 06/27/05
Your bias is showing  Squawkbox | 06/27/05
How Is That Bias?  itanalyst | 06/27/05
At least you did not deny the Troll Status  Squawkbox | 06/27/05

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here