• On The Insider: Miley Cyrus in Sex and the City 2
January 13, 2009 10:40 AM PST

Microsoft fixes holes in Server Message Block

by Elinor Mills
  • Font size
  • Print
  • 5 comments
Share

Updated at 12:50 p.m. PST to clarify that Windows Vista and Server 2008 are not affected by the SMB Buffer Overflow Remote Code Execution vulnerability, but are affected by the other two vulnerabilities.

Microsoft on Tuesday released a security update that fixes three vulnerabilities in the Windows network file-sharing protocol Server Message Block (SMB) that could allow an attacker to remotely take complete control of a system.

Microsoft Security Bulletin MS09-001, part of the Patch Tuesday bulletin for January, is rated critical for Microsoft Windows 2000, Windows XP and Windows Server 2003, and moderate for Windows Vista and Windows Server 2008. Windows Vista and Windows Server 2008 are not affected by the SMB Buffer Overflow Remote Code Execution vulnerability.

The buffer overflow remote code execution vulnerability arises from the way the SMB protocol handles specially crafted SMB packets. Meanwhile, an attempt to exploit the SMB Validation Remote Code Execution Vulnerability would not require a user name or password. Most attempts to exploit those weaknesses would result in a system denial of service, however remote code execution is "theoretically possible," Microsoft said.

Using a firewall and having a minimum number of ports open can help protect networks against attacks, the company said.

"Blocking TCP ports 139 and 445 at the firewall will help protect systems that are behind that firewall from attempts to exploit this vulnerability," the bulletin says. "Microsoft recommends that you block all unsolicited inbound communication from the Internet to help prevent attacks that may use other ports."

Blocking connectivity to the ports may interfere with the function of certain services, including file and print sharing, fax, computer browser, and net log-on.

The SMB Buffer Overflow Remote Code Execution and SMB Validation Remote Code Execution vulnerabilities were reported by an anonymous researcher working with TippingPoint and the Zero Day Initiative. The SMB Validation Denial of Service vulnerability had been publicly reported.

Microsoft had issued a notice on Thursday saying it would issue one security update on Patch Tuesday. A Webcast is scheduled for 11 a.m. PST on Wednesday.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
PC Tools Internet Security 2010 reviewed
Google Chrome now bundled with Avast
Some Avast users must reinstall flagged files
Defense Dept. pulls software over privacy issues
Microsoft to plug critical IE hole targeted by exploit code
Google wants to unclog Net's DNS plumbing
Avast update falsely flags good apps as malware
Character limitations in passwords considered harmful
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by Penguinisto January 13, 2009 11:12 AM PST
Disjointed sentence up there, it ends: "and moderate for Windows Vista and Windows Server 2008. Windows Vista and Windows Server 2008 are not affected."

Either they are affected (which requires the patch) or they are not (which means the patch would have been rated far lower than "moderate", dontchathink?)
Reply to this comment
by smilin:) January 13, 2009 2:06 PM PST
Buffer overflow almost always result in a system failure of some sort due to corruption, DEP kicking in etc.. To further leverage a buffer overflow to insert code requires circumventing additional protections that Vista and 2008 have.

Vista/2008 may have the buffer overflow but their architecture means they are not affected by a remote execution vulnerability. Remote execution is considered 'critical'. A non exploitable buffer overflow would be 'moderate'

The statement appears correct although it could use some clarification.

We'll never have software with 60+ million lines of code turn out perfect but MS investment in a more secure architecture seems to be paying off every time some flaw is found somewhere.
by roland827 January 13, 2009 11:42 AM PST
They claim it is moderate since most access to Vista systems results in the annoying pop up requesting users to approve or deny access to a particular program. Although this is usually dismissed by people (by clicking ok) and not even read, it can still affect vista due to force of habit by users who are basically just fed up with that popup....
Reply to this comment
by MSSlayer January 13, 2009 2:52 PM PST
The genius of MS, blame users for getting exploited.
by krillin6 January 14, 2009 2:34 PM PST
The Vista User Account Control is stupid, yes. It can also be turned off, which isn't good enough when you want to say users are the issue. Also, UAC should always be turned off; it is annoying.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right