Quantcast

Microsoft Patches Flaw That Could Trigger Worm Attack

Robert McMillan, IDG News Service

  • 0 Yes
  • 0 No

With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Other Patches

The critical MS08-001 update that fixes this flaw also patches a second, less-serious bug in the Windows networking stack that could be leveraged to launch a denial of service attack against a Windows system. This vulnerability lies in the Internet Control Message Protocol Router Discovery Protocol (ICMP RDP) which is used by Windows to find out how to communicate with the network. Because this capability is not turned on by default, Microsoft considers this to be merely an "important" bug.

Microsoft's other Tuesday update, MS08-002, fixes an elevation of privilege flaw in the Windows Local Security Authority Subsystem Service (LSASS), used to manage account credentials in Windows.

This flaw could be exploited by attackers to steal passwords or run their code with a higher level of privilege on Windows, said Schultze. "The primary concern is Johnny who is a user becoming Johnny admin," he said. But if attackers were to combine an attack that exploited this flaw with another exploit that would allow them to run code on the system, then "that could become a critical issue," he said.

  • Recommend this story?
  • 0 Yes
    0 No

"Microsoft Patches Flaw That Could Trigger Worm Attack" Comments

Related Windows Articles

  • CDW Virtualization Center What is Virtualization and how can it help you save money? Click here to find out.
  • Try it Free Center An assortment of free software and free trial offers to choose from. Check it out!
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)