On TechRepublic: FREE download: Social networking policy
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Dec 1, 2005 10:11:00 PM

Two new pieces of computer code that could be used in cyberattacks on Windows users were posted on the Web on Wednesday and Thursday.

The exploit posted Thursday is another that could allow a remote attacker to gain complete control over a vulnerable computer. The code takes advantage of a flaw in a Windows component for transaction processing, called the Microsoft Distributed Transaction Coordinator. Microsoft addressed the flaw in security bulletin MS05-051 in October.

The attack code published Wednesday is another that exploits a flaw in the way Windows handles certain graphics files and could cause a vulnerable system to crash. Microsoft provided a patch for the flaw in November with security bulletin MS05-053 and warned that the vulnerability could create an opening for spyware and Trojan horse attacks.

Including these last two, a total of four exploits have been released for the same two Windows flaws since Sunday, according to the French Security Incident Response Team, a security research company.

"It is reasonable to assume as we have seen so much proof-of-concept code distributed for these vulnerabilities that we will eventually see some class of attack," said David Marcus, security research and communications manager at McAfee.

While availability of attack code could provide cybercriminals with ammunition, patches and security software should shield Windows users, said Steve Manzuik, security product manager at eEye Digital Security.

"I am sure some will try and use the exploits, but the reality is there are patches for these issues and almost every security vendor would have by now added signatures to protect against this stuff," Manzuik said.

Michael Sutton, director at security intelligence company iDefense, a part of VeriSign, agreed. "These vulnerabilities were patched, so fortunately clients have had weeks to patch," he said.

Unpatched IE bug is bigger threat
Microsoft is not aware of any attacks that use the latest exploits. However, the company warned this week of an attack that uses a yet-unpatched flaw in Internet Explorer. At least one exploit for that vulnerability also has been publicly released in the past two weeks.

"That's the biggest threat out there, the Microsoft Internet Explorer vulnerability which has no patch," Manzuik said. "Currently there are exploits on the Web for this that are not that malicious, but it wouldn't be too hard for someone to take this and make it malicious."

Sutton also warned computer users to be on guard for exploitation of the unpatched bug. "The one to pay attention to is the vulnerability that remains unpatched. Microsoft has released an advisory for this but no patch yet," he said. Microsoft may issue a fix outside of its monthly patching cycle for this problem, Sutton said.

Microsoft's next monthly patch release is scheduled for Dec. 13.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 28 Talkback(s)
Let me give you an answer.
"Is it worse to have 4 exploits for 1 vulnerability or to have only
1 exploit?"

If your system isn't patched* It is much worse to have multiple
exploits, because, if your system isn't p... (Read the rest)
Posted by: Haterock Davidsfather Posted on: 12/03/05 You are currently: a Guest | | Terms of Use
This is so common no one cares to comment anymore (NT)  too_much green_tea | 12/01/05
except..  Jeff Spicoli | 12/01/05
Then why...  Haterock Davidsfather | 12/01/05
Then why... do some people still not get it?  Jeff Spicoli | 12/01/05
Bravo , bravo !!!  I'm Ye, the MS SHILL . | 12/01/05
thankie Mr. Rooty  Jeff Spicoli | 12/01/05
Aw, c'mon. Be nice!  B.O.F.H. | 12/01/05
Out of curiosity  too_much green_tea | 12/01/05
Lemme fill you in  Jeff Spicoli | 12/01/05
it does have a flaccid ring to it, doesn't it?  Jeff Spicoli | 12/01/05
Nice...  toadlife | 12/01/05
That's funny  Jeff Spicoli | 12/01/05
Oh I'm sorry, I should have known.  toadlife | 12/01/05
no need for sensitivity  Jeff Spicoli | 12/02/05
happy  too_much green_tea | 12/01/05
That was cute, eh?  Jeff Spicoli | 12/01/05
Thursday  Len Rooney | 12/01/05
Thursday  Len Rooney | 12/01/05
Let me ask a question  NonZealot | 12/01/05
Just to nit pick here...  Cardinal_Bill | 12/01/05
Let me give you an answer.  Haterock Davidsfather | 12/03/05
Darn you zdnet geeks have been busy  Boot_Agnostic | 12/01/05
class of attack  ipfresh@... | 12/02/05
Complacency  whisperycat | 12/02/05
Wait...I'll take this one....  timoute | 12/02/05
Wait...I'll take this one....  timoute | 12/02/05
Ooopppss....  timoute | 12/02/05
Whatever...YAAAAWN!!!!  btljooz | 12/02/05

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here