Version: 2008
  • On TV.com: Julie is HOT (and so is TV in a FLASH)

October 13, 2005 3:20 PM PDT

Exploit code raises Windows worm alarm

  • 4 comments
Related Stories

Microsoft plugs Windows worm holes

October 11, 2005

Windows worms knocking out computers

August 16, 2005
Computer code has already been written to take advantage of Windows flaws that were disclosed Tuesday, a sign that a worm attack could be near.

Exploit code exists for four of the 14 vulnerabilities for which Microsoft provided fixes this week, experts said Thursday. One of the exploits was written for a flaw which Microsoft tagged as "critical." The bug lies in a Windows component for transaction processing called the Microsoft Distributed Transaction Coordinator, or MSDTC.

"When we start to see exploits surfacing, we know there will shortly be malicious code," said Alfred Huger, a senior director at Symantec Security Response. "We expect at least the MSDTC vulnerability to be used in a worm in the short term."

After Microsoft released vulnerability information, the exploit code was written within 24 hours, noticeably quicker than the average time it takes for an exploit to appear, Huger said. "Over the last two years on average it has been between four and 5.8 days for an exploit to come out after a vulnerability was released," he said.

When Microsoft released its patches on Tuesday, experts had already warned that the MSDTC flaw could spawn an attack similar to the Zotob worm that wreaked havoc two months ago. Microsoft urged users of older operating systems, specifically Windows 2000 and Windows XP before Service Pack 2, to prioritize the update that fixes the flaw, which is addressed in security bulletin MS05-051.

The MSDTC exploit isn't publicly available, but experts predict a public exploit is not far off. The code was created by security vendor Immunity for users of its penetration testing product. Immunity also crafted exploits for a flaw that involves plug-and-play in Windows (MS05-047) and a bug in a component that supports Novell NetWare networks (MS05-046).

Furthermore, code that exploits a flaw in Microsoft's Windows FTP client (MS05-045) is available publicly on the Internet, said Michael Sutton, director at security intelligence company iDefense, a part of VeriSign.

"Patching is very urgent," Sutton said. "We expect public exploit code to become available, especially for the MSDTC issue."

Microsoft is aware of Immunity's exploit code, but has not seen any attacks that use the code, a company representative said. "Microsoft is actively monitoring this situation," the representative said in an e-mailed statement.

Symantec's Huger predicts a worm exploiting the MSDTC flaw will surface in the next several days. It is unknown how hard the worm will hit. "There are so many variables involved with that, it is tough to say," he said.

See more CNET content tagged:
exploit, flaw, expert, worm, vulnerability

Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
Hope it hits hard
by October 13, 2005 3:50 PM PDT
I hope this worm hits hard, more specificly, hits Microsoft hard. When there are coders out there that write exploits.. what do you expect to happen when you publicly announce that you have a vulnerability in a specific part of an OS. Why don't they wise up, say they have a vulnerability, release the patch, but don't say what it is. Make the coders work for the exploit they wish to write. It's just that simple.
Reply to this comment
Unreasonable expectations
by aabcdefghij987654321 October 14, 2005 6:28 AM PDT
Most companies only install patches that they are told are important and that they believe may affect them. If you don't tell what the problem is and stress the severity of it, many companies will simply opt not to install the patch.

Likewise once the patch is released a hacker can compare the original unpatched code to the patched code and figure out exactly how to write an exploit of any patched software that fixes an exploitable problem.
Hope it hits hard
by October 13, 2005 3:50 PM PDT
I hope this worm hits hard, more specificly, hits Microsoft hard. When there are coders out there that write exploits.. what do you expect to happen when you publicly announce that you have a vulnerability in a specific part of an OS. Why don't they wise up, say they have a vulnerability, release the patch, but don't say what it is. Make the coders work for the exploit they wish to write. It's just that simple.
Reply to this comment
Unreasonable expectations
by aabcdefghij987654321 October 14, 2005 6:28 AM PDT
Most companies only install patches that they are told are important and that they believe may affect them. If you don't tell what the problem is and stress the severity of it, many companies will simply opt not to install the patch.

Likewise once the patch is released a hacker can compare the original unpatched code to the patched code and figure out exactly how to write an exploit of any patched software that fixes an exploitable problem.
(4 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (1.66%) 0.29 17.71
Microsoft (1.65%) 0.47 28.99
Dow Jones Industrials (2.03%) 203.52 10,226.94
S&P 500 (2.22%) 23.78 1,093.08
NASDAQ (1.97%) 41.62 2,154.06
CNET TECH (2.03%) 31.22 1,569.62
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right