User: Pass: Forget password? / Register New User 
Current issue Current issue | Forum and Community Forum & Community | Onekit's Software OneKit's Software | Submit software (submit PAD file) Submit software
home | links | about / contact us
Games Graphics & Design MP3 & Audio Internet & Networks System & Utilities Home & Education Business WebDev SoftDev
Reviews & Articles :: Exploit code threatening Windows PCs
Issue: July 2006 > System & Utilities > Article "Exploit code threatening Windows PCs"

Exploit code threatening Windows PCs (Exploit code threatening Windows PCs)  Exploit code threatening Windows PCs

System & Utilities
Advertisement on Onekit.com Software Magazine
Two pieces of computer code that could be used to cause attacks have been released onto the Internet

Two new pieces of computer code that could spawn attacks on Microsoft Windows PCs have been released onto the Internet, security companies have warned.

The first exploit code takes advantage of a "critical" flaw in the Windows Dynamic Host Configuration Protocol, or DHCP, client, according to a customer alert sent out by the French Security Incident Response Team on Monday. Microsoft released a fix on 11 July for the problem, Symantec said in its own advisory for subscribers.

An attacker could gain full control over an unpatched Windows computer using the exploit, Symantec said.

Microsoft tackled the problem in security bulletin MS06-036, and people who have applied that update are protected, a representative for the software maker said.

The second, proof-of-concept code targets a security hole in a Windows component called "mailslot", which Microsoft patched in bulletin MS06-035, Symantec and FRSIRT said. However, Microsoft said it believes the code takes advantage of a new flaw.

"Proof-of-concept code was published on the Internet for a variant of the vulnerabilities addressed by Microsoft security update MS06-035," the representative for the software maker said. The company is monitoring this situation and may issue another patch, to fix the variant, the representative added.

Security experts pointed to the "mailslot" vulnerability as the most risky in Microsoft's July patch bunch. It could be used to spread a worm, they warned. However, the proof-of-concept code released over the weekend does not have as severe an effect; all it can do is crash a computer, Symantec said.

Microsoft said it is not aware of any actual attacks that use either of the two exploit-code samples, the representative said.

The company issued seven security bulletins with fixes for 18 flaws earlier this month. At least two of the vulnerabilities were already being exploited in attacks prior to the patches being released, security company iDefense has said. Also, soon after the monthly Patch Tuesday bulletins were released, miscreants launched attacks that exploit a new PowerPoint flaw.



Related Links:
July 26, 2006
Author: Joris Evers
There are no users' comments | Post your comment
Copyright 2003-2008 - Software Magazine, onekit.com, Legal Notices

You can help improve OneKIT and boomerang will come back.
Advertisement Advertisement
Sponsored links: Shareware downloads | Hard Drive Recovery | Firevector