Exploit code puts Windows XP and 2000 at risk

Exploit code has been published that could take advantage of flaws in Windows XP SP1 and Windows 2000 SP4, according to a warning issued Thursday in the United States by Microsoft.

Although the exploit code could be used to launch a denial-of-service (DOS) attack in machines running XP SP1 and Windows 2000 with all service pack versions, the threat is only moderately severe, said Stephen Manzuik, product manager for security researcher eEye Digital Security.

"On a scale of 10, it would be about a four or five on severity," said Manzuik. "All it will do is crash some machines and not crash others."

The exploit code could launch a remote DOS attack on Windows 2000 machines using all service pack versions, but would require a user authentication on Windows XP SP1 computers, Manzuik said.

The exploit poses only a moderate risk because it requires a user to log on for Windows XP, and in the case of Windows 2000, the attacker would have to get remote access to the Remote Procedure Code (RPC) port. That port is often behind a firewall, making it difficult to penetrate remotely, Manzuik noted.

Microsoft has yet to develop a security patch for this exploit, but it recommended that users enable their firewalls and download security updates, according to its security advisory.

The exploit code was published by Winny Thomas of Nevis Labs in India, while Thomas was reverse engineering a patch Microsoft issued in October, according to a posting on FrSIRT's Web site. The patch, MS05-047, dealt with a plug-and-play feature in the Windows software.

"While working on an exploit for MS05-047, I came across a condition where a specially crafted request to upnp-getdevicelist would cause services.exe to consume memory to a point where the target machines virtual memory gets exhausted. This exploit is not similar to the MS05-047 exploit I published earlier," Thomas noted in his posting.

The October patch did not create the latest vulnerability in Windows, a Microsoft spokeswoman said. She added Microsoft encourages users to "apply the MS05-047 update and all recent security updates released by Microsoft."

Microsoft, however, reiterated its concerns over security researchers who publish details on how to exploit vulnerabilities before the software vendor has had time to create a patch.

"Microsoft is concerned that this new report of a vulnerability in Windows 2000 SP4 and Windows XP SP1 was not disclosed responsibly, potentially putting computer users at risk," the company stated. "We continue to encourage responsible disclosure of vulnerabilities."

Some security researchers, however, note that Microsoft has been known to take at least 200 days or more to issue a security patch, once the company has been notified of a problem.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured