Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Blogs

Race is On to Patch Critical Windows Flaw

Tony Bradley, PC World

Security experts are concerned about the potential impact of a new security hole affecting the Windows operating system. The potential exists to create a worm that would allow an attacker to take complete control of vulnerable systems without any user interaction--a jackpot for malware developers.

This past Tuesday was Microsoft's big patch release day for the month of September. Microsoft released a total of five new Security Bulletins, all of them rated Critical. Microsoft quickly followed the regularly scheduled patch release with a Security Advisory warning of the new unpatched flaw.

The flaw impacts Windows Vista and Windows Server 2008 systems. Windows Server 2008 R2 is not affected, and Microsoft resolved the flaw in the RTM version of Windows 7, but systems using Windows 7 RC are vulnerable as well.

The issue lies in the Windows network file sharing protocol, SMB (server message block). Initial proof-of-concept attacks simply resulted in system crashes- the infamous (or is it notorious?) Blue Screen of Death. However security experts have determined that it is possible to leverage this flaw to execute malicious code remotely on vulnerable systems. Microsoft updated the Security Advisory to acknowledge the potential threat.

Microsoft will certainly be rushing to develop, test, and release a patch for affected systems. That means the clock is ticking and the race is on. Malware developers have a window of opportunity to take advantage of this vulnerability and develop a Conficker-like worm able to spread and infect systems without any user intervention.

The fact that this vulnerability is limited to Windows Vista (and Windows 7 RC) desktops means that only about 30 percent of the Windows desktops are potential targets. For once the sluggish acceptance of Windows Vista is a good thing.

If you are using Windows Vista (or Windows 7 RC), you need to take some steps to protect yourself during the window of opportunity. You don't want to get caught with your proverbial pants down while waiting for a patch from Microsoft.

The simplest solution would seem to be to upgrade. Microsoft made evaluation versions of Windows 7 RTM available last week. You could download the evaluation and upgrade, but be warned that you will have to actually buy Windows 7 by the time your evaluation period is up, and that moving from the evaluation to the official release requires installing everything from scratch.

If upgrading seems like too much of a burden, or just doesn't seem practical for you, there are some other mitigating steps you can take. First, you can disable the SMB service on vulnerable systems. Doing so will protect the system from any potential exploit of this vulnerability, but will also prevent the system from being able to access network resources.

Another solution is to ensure that TCP ports 139 and 445 are blocked at the network firewall. This solution will prevent SMB traffic from external sources while still allowing the vulnerable systems to access network resources internally.

Tony Bradley is an information security and unified communications expert with more than a decade of enterprise IT experience. He tweets as @PCSecurityNews and provides tips, advice, and reviews on information security and unified communications technologies on his site at tonybradley.com.

  • Recommend this story?
  • 0 Yes
    0 No

"Race is On to Patch Critical Windows Flaw " Comments

 
Learn more about the Windows Phone PCWorld Gift Guide

People who read this also read:

BizFeed

  • Hacked Climate Change E-mails Highlight Security Concerns In the heat of the climate change debate sparked by hacked e-mail messages, there has been little discussion of how the e-mails were leaked. In a connected world, security and privacy are both more important, and harder to come by.
  • Five Reasons the Google Chrome OS will Flop The Google Chrome OS is generating excitement, but it doesn't seem to be compelling enough to be worth the hype. Here are five reasons Chrome will ultimately fail to impress.
  • Confessions of an Office 2010 CTP Tester Microsoft released the public beta of Office 2010 yesterday, but I have already been using Office 2010 for the past four months. Here are my thoughts on the new Office.
  • Google's Chrome May Shift the OS Landscape Google is providing a sneak peak at the Chrome OS today. Maybe the Google Midas touch can succeed where decades of Apple and Linux have failed--denting Microsoft’s OS dominance.

All PC World Blogs

Sponsored Links