Saturday February 11, 2012 9:24 AM AEST

Microsoft Patch Tuesday bug is scary

By The Inquirer
09:40 Jan 15, 2009
Tags: Microsoft | Patch | Tuesday | bug | is | scary
Microsoft Patch Tuesday bug is scary

Or at least that's what the security experts are saying.

The first Patch Tuesday fix of 2009 put out by Microsoft addresses a dangerous security vulnerability in its Server Message Block (SMB) protocol, or so say some insecurity experts.

Microsoft says it believes that exploits are unlikely, rating patch MS09-001 at a three on its exploitability index scale. But researchers say users should not neglect to apply the patch, because a successful exploit would enable an attacker to execute arbitrary code or mount a denial-of-service attack without first needing to steal a password to acquire authorisation.

That's because the vulnerability exists in Netbios protocol ports, which are "almost always guaranteed to be open for Windows to function," according to Amol Sarwate, manager of Qualys' vulnerability research lab.

The patch is labeled 'critical' for Windows XP, 2000 and 2003, because those versions have Netbios enabled by default, but is tagged as only 'moderate' for Windows Vista and Server 2008, since those versions have Netbios disabled by default. Many corporate servers have Netbios ports open because those are used for performing remote management activities.

However, unless remote attackers can construct TCP packets that encapsulate malicious Netbios datagrams, most servers should not be terribly vulnerable, because Netbios is an unroutable protocol.

Unless of course the attackers are inside your firewall, on your LAN.

 

theinquirer.net (c) 2010 Incisive Media

 
Behind the scenes with Mass Effect 3! GTX 560 VGA round-up! Essential Skyrim tweaks to improve your game! Plus reviews, news, hardware, more games, and easy to following modding guides for PC builders. ON SALE NOW!
 
Latest Competitions
 
Atomic Magazine

Issue: 133 | February, 2012

Atomic is a magazine aimed squarely at computer enthusiasts, gamers, and serious PC upgraders.

Every month we bring you the latest reviews of new technology and PC components, in depth features on everything from overclocking to console hacking, and gaming previews and interviews.
 
Latest Comments
 
Latest User Reviews
Battlefield 3 is the new benchmark online FPS
90%
A very fun and realistic multiplayer ride.
 
Antec Kuhler 920 - liquid cool
90%
Antec Kuhler 920 silent but effientive out of the box no maintence water cooling kit
 
Antec's Lanboy Air - our new favourite case
90%
Antec Lan boy Air in red a very cool design
 
Antec's Lanboy Air - our new favourite case
90%
This product overall is awesome.
 
MSI's GT780 laptop as fast as it gets
90%
Nice laptop
 
 
Close Get the February, 2012 issue of Atomic mailed to you for $8.95, including postage.

Buy nowDigital Version