• On CBSSports.com: Mike Tyson's daughter dies in accident
October 16, 2008 12:45 PM PDT

Microsoft Host Integration Server flaw exploited

by Robert Vamosi

On Thursday, new code was posted on the Internet that could exploit a flaw in unpatched Microsoft Host Integration Servers.

The exploit is part of Metasploit, a toolkit used by penetration testers and criminal hackers alike.

On Tuesday, Microsoft issued security bulletin MS08-059 to address the vulnerability detailed in CVE- 2008-3466. In its patch bulletin, ranked as critical, Microsoft said "this vulnerability could allow remote code execution if an attacker sent a specially crafted remote procedure call request to an affected system. Customers who follow best practices and configure the systems network architecture remote procedure call (SNA RPC) service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights."

Apparently Microsoft knew of the exploit. To help system administrators prioritize the patches an "Exploitablity Index" was inaugurated with the October Patch Tuesday releases. Microsoft gave MS08-059 a 1 for having "for consistently functioning exploits". Other index ratings include 2 for "inconsistently functioning exploits" (of moderate concern), and 3 for vulnerabilities that are "unlikely to produce functioning exploits" (of least concern).

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Security
Symantec's Ramzan on solving the antivirus puzzle
Apple fixing iPhone SMS security hole
Waledac worm targeting July 4 spam offensive
ATM vendor gets security talk pulled from conferences
Postini: Google's take on e-mail security
Botnets lead the way for spam
Stallman warns of Mono 'risk'
China delays rule for Net-screening software
Add a Comment (Log in or register)
by tacit October 16, 2008 1:03 PM PDT
" In it's patch bulletin, ranked as critical..."

C'mon, C-Net. You're supposed to be professional writers here. This is the second time I've seen an editor let this error slip so far this week.

It should read " In its patch bulletin, ranked as critical..."

"It's" means "it is." You do not use "mi'ne" or "hi's" or "her's" or "it's" for possessive. It's at least understandable when folks who aren't paid professional writers make this error, but professional writers with editors should know better.
Reply to this comment
by Vegaman_Dan October 16, 2008 2:08 PM PDT
There was a vulnerability, it was patched and is no longer an issue.

Is there news in this?
Reply to this comment

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right