Quantcast

Exploit Goes Public for Windows DNS Server Bug

Microsoft acknowledges a critical vulnerability in its server software, which one security company says "greatly increases" the chances of a broad attack.

Gregg Keizer, Computerworld

  • 0 Yes
  • 0 No

A public exploit appeared just two days after Microsoft acknowledged a critical vulnerability in its server software, a change one security company said "greatly increases" the chances of a broad attack.

The zero-day bug in the Domain Name System (DNS) Server Service in Windows 2000 Server (SP4) and Windows Server 2003 (SP1 and SP2) was confirmed by Microsoft late on Thursday. On Friday, the company said the current beta of Longhorn Server, the next-generation server software expected to ship later this year, was also affected.

Symantec warned Saturday that the Metasploit Project had released a public exploit for the vulnerability. "The release of this exploit greatly increases the chance of widespread exploitation of this issue before a patch is made available," warned Symantec. Metasploit is a security testing tool largely guided by developer and researcher HD Moore and is frequently first out the gate with exploits of Windows vulnerabilities.

Ken Dunham, director of VeriSign's iDefense rapid response team, also noted the importance of the Metasploit release. "[This changes] the threat landscape for this issue," he said in an e-mail.

Microsoft modified its advisory late Friday and again Sunday to offer more detailed defensive recommendations and note that Microsoft Windows Small Business Server 2000 and Small Business Server 2003 are also at risk.

Go to Computerworld to read the rest of the story.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

"Exploit Goes Public for Windows DNS Server Bug" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

PC World's Marketplace