Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: MISCELLANEOUS

MS09-001 - It's A Big(-ish) Deal This Time

Date: 01/19/2009
Author: Razvan Stoica

Covering again the vulnerability beat this week, only from a more mundane angle: this one's a biggie, folks and folkettes, and you'd be well-advised to let Windows auto-update do its thing (or at least, test and patch at your earliest convenience, but then, if that kind of thing is part of a regular breakfast for you, what are you doing here?).

MS09-001 resolves three vulnerabilities in the SMB protocol implementation, two of them leading straight to unauthenticated, remote code execution (read: total ownership of affected systems on a first-come-first-serve basis) and a mere denial of service condition.

Before you start thinking that these are all bad things that may happen in your future and hence ignorable, take a moment to appreciate the facts.

All versions of Windows up to and including 7 are vulnerable in their unpatched state, firewalled systems may be spared yet corporate PC's rarely are firewalled from one another - which would give a potential worm plenty of room to spread - and that, in fact, there is a rumour around the block that there may already be exploit code in the wild for one or more of these vulnerabilities.

Patch now. Nobody would benefit from two Downadup-sized epidemics in one month - except virus writers.


Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
March 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
293031    
« Feb March Apr »
Tag Claud
message canadian messages word exploit twitter virus review data bitdefender spam antivirus system file infected computer malware conficker rogue worm microsoft online pharmacy security downadup omelette software windows files trojan