Attack code for Windows flaw heightens risk

Computer code that exploits a "critical" vulnerability in Windows has been released on the Internet, prompting Microsoft to issue a security advisory.

The attack code takes advantage of a flawed Windows routing and remote access component for which Microsoft released a patch two weeks ago, the company said in its advisory published late Friday. The company is not aware of any actual cyberattacks that use the exploit code, it said.

"An attacker who successfully exploited this vulnerability could take complete control of the affected system," Microsoft said.

Microsoft urges users to apply the fix delivered with security bulletin MS06-025, which will remove the vulnerability. "We have confirmed that the exploit code does not affect users who have installed the update," Microsoft said.

However, the MS06-025 fix can interfere with a certain dial-up networking connections, Microsoft said last week. The company advised people who use dial-up scripting or terminal window features to not install the security update while it works on a revised patch. That revision is still in the works, a Microsoft representative said Monday in the US.

The MS06-025 update was one of a dozen security bulletins that Microsoft released weeks ago. At least one patch came after the vulnerability it addressed had already been exploited in a cyberattack. Exploits for some other flaws have also been released, further increasing the urgency to patch.

Advertisement

Talkback 0 comments


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured