Flaw and Exploit in Latest Windows and Windows Server? Check.
- Dr. Roy Schestowitz
- 2009-09-30 00:19:06 UTC
- Modified: 2009-09-30 06:23:34 UTC
Summary: A critical vulnerability lacking any real patch has now an attack code which puts in jeopardy Windows Vista Service Pack 1, Service Pack 2, even Windows 2008 Service Pack 1 (soon 2)
For context, see:
Microsoft 'Fixes' Windows Vista and Windows Server 2008 by Disabling Entire Features
Now comes this:
●
Exploit published for SMB2 vulnerability in Windows
A fully functional exploit for the security vulnerability in the SMB2 protocol implementation has been published. It can be used to discover and attack vulnerable Windows machines remotely. By integrating the exploit into the Metasploit exploit toolkit, attackers have access to a wide range of attack options, ranging from issuing a warning to setting up a convenient backdoor on a user's system.
●
Hackers release new attack code for Windows
On 18 September Microsoft released a Fix-It tool that disables SMB 2, and the company said then that it was working on a fix for its software.
●
Pressure on Microsoft, as Windows Attack Now Public
Metasploit developer HD Moore said Monday that the exploit works on Windows Vista Service Pack 1 and 2 as well as Windows 2008 SP1 server. It should also work on Windows 2008 Service Pack 2, he added in a Twitter message.
Will Microsoft do better than
with XP?
⬆