Microsoft: Patch Server Vulnerability to Combat New Attacks

Microsoft has reiterated its recommendation that companies deploy the patch to correct a flaw affecting the Windows Server service that was fixed last October.

The latest attacks are coming courtesy of a new variant of the Conficker worm, identified by Microsoft as Win32/Conficker.B. According to Microsoft, the variant is hitting computers that have not applied the fix, while also spreading via network shares by attempting to log in to machines using a list of weak passwords.

The worm exploits a vulnerability caused by the Server service failing to properly handle specifically-crafted RPC (remote procedure call) requests. If an exploit is successful, it could allow an attacker to execute code remotely when file sharing is enabled.

The issue was the subject of a rare out-of-band security patch by Microsoft last October 23rd. As attacks mounted, Microsoft issued a follow-up warning in its Security Response Center blog a month later.

“We encourage all customers to apply our most recent security updates to help ensure that their computers are protected from attempted criminal attacks,” a Microsoft spokesperson said.

The Windows firewall also provides a defense against attacks in a default setting because as it blocks hackers from reaching the RPC interface.

The flaw affects users of Microsoft Windows 2000, Windows XP and Windows Vista, as well as Windows Server 2003 and Server 2008. On Windows 2000, XP and Server 2003, any anonymous user with access to the target network can deliver a specially crafted network packet to exploit the vulnerability. However, on Vista and Server 2008 systems, only an authenticated user with access to the target network can deliver the packet.

“By default, Microsoft Windows XP, Windows Vista, Windows Server 2003 and Windows Server 2008 customers will have this update applied automatically through Automatic Updates,” the spokesperson said. “We encourage all customers to apply our most recent security updates to help ensure that their computers are protected from attempted criminal attacks.”

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

1 day ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

1 day ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

2 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

2 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

2 days ago