Cybercrooks exploiting new Windows DNS flaw

Cybercrooks are using a yet-to-be-patched security flaw in certain Windows versions to attack computers running the operating systems, Microsoft warned late last week.

The attacks target Windows Server 2000 and Windows Server 2003 systems through a hole in the domain name system, or DNS, service, Microsoft said in a security advisory. The attacks happen by sending rigged data to the service, which by design is meant to help map text-based Internet addresses to numeric Internet Protocol addresses.

"An anonymous attacker could try to exploit the vulnerability by sending a specially crafted RPC packet to an affected system," Microsoft said in the advisory. RPC, or Remote Procedure Call, is a protocol that applications use to request services from programs on another computer in a network. RPC has been involved in several security bugs before, including in the vulnerability that let the Blaster worm spread.

The French Security Incident Response Team deems the Windows DNS vulnerability "critical," its highest rating.

The DNS and RPC warning comes days after Microsoft issued its April security patches. At the same time security experts have issued warnings on multiple zero-day flaws in Office and another one in Windows.

The latest vulnerability is a stack-based buffer overrun, Microsoft said. This is a common type of coding problem that has caused many headaches for Microsoft and Windows users. A successful attack will give full control over a vulnerable machine without any user interaction, Microsoft said.

There are "limited attacks" that exploit the issue, Microsoft said. The software maker said it is finishing a security update for Windows to repair the problem. Microsoft did not say when it plans to release the update. The company's next "Patch Tuesday" is on May 8, though if attacks increase a patch could be released out of that cycle.

While it works on the fix, Microsoft suggests several work-arounds for users of affected Windows versions. These include disabling remote management over RPC capability for DNS servers, blocking specific data ports using a firewall and enabling advanced filtering. Security firm Symantec on last week urged users to apply the work arounds.

"Customers are advised to...apply the appropriate work-arounds as soon as possible, in the event that the attacks become more widespread," Symantec said in an alert sent to subscribers of its DeepSight security intelligence service.

Windows XP and Windows Vista are not impacted by the DNS flaw. Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 are vulnerable, Microsoft said.

Like this article? Click below to send it to your mobile for free!

Talkback 1 comments

  1. HAHAHAHA! Anonymous -- 16/04/07

    When will you idiots learn! Get a Mac and live FREE from the fear and effects of viruses, malware, and vulnerabilities. Every week there is another exploit that lets hackers completely take over your Windoze box. That has NEVER HAPPENED ON A SINGLE OS X MACHINE!!

    Please people, Get a Mac so I stop getting SPAM sent from YOUR CRAPPY WINDOZE COM-PYU-TER!


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured