Windows SMB2 Vulnerability: Ability to Run Unauthorized Software on Exploited Vista PCs

GoldSparrow By GoldSparrow in Computer Security | 0 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

A new code created by hackers that is designed to exploit a critical bug in Microsoft Windows operating system, has been released publicly. The public release of this code, or SMB2 vulnerability attack code, puts pressure on Microsoft to quickly come up with a fix to the flaw before it results in an outbreak of a computer worm that infects computers running Windows Vista SP1, Vista SP2, Windows 2008 SP1 Server and Sever SP2.

Stephen Fewer, Harmony Security’s Senior Researcher, has developed a new attack revealing that an attacker can run unauthorized software on an exploited computer. This in itself can escalate into a much bigger problem. Fewer’s test code, as well as many others attack codes, have been added to an open-source penetration testing kit called Metasploit which is a computer security project that helps provide information about vulnerabilities and penetration testing.

This new SMB (server message block) Version 2 vulnerability has been known since September 7th of this year but remains to be un-patched. Other companies have developed their own attack code that exploits the same bug within Windows and added it to Metasploit. Because virtually anyone can download Metaspolit, the code can be used to attack Windows PC’s. However, there remains to be a drawback in using the open source code, it only works on Windows Vista machines according to Immunity Senior Researcher Kostya Kortchinsky.

In a way, the public release of attack code to exploit a vulnerability within several versions of Windows, will force Microsoft to come up with a fix. Ultimately, this is the goal for many security researchers. Even though the bug is not known to affect other popular versions of Windows such as XP, Sever 2003, Windows 2000 and the upcoming Windows 7, it remains to be a viable threat if it is not resolved.

This flaw does not affect Windows XP, Windows 2000 and Windows Sever 2003 mainly due to the reason that this exploit resides in the SMB (server message block) version 2 system, which was first introduced in Vista. As you may know, Windows Vista came out after XP, Windows 2000 and Sever 2003. Windows 7 would be another target for this bug only it has been patched according to Kostya Kortchinsky.

The next security patch from Microsoft should be released on October 13th but researchers are still unclear if it will include a fix to the SMB (SMBv2) vulnerability.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 09/30/09 and is filed under Computer Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.