Security

Read all 'Metasploit' posts in Security
October 16, 2008 12:45 PM PDT

Microsoft Host Integration Server flaw exploited

by Robert Vamosi
  • 2 comments

On Thursday, new code was posted on the Internet that could exploit a flaw in unpatched Microsoft Host Integration Servers.

The exploit is part of Metasploit, a toolkit used by penetration testers and criminal hackers alike.

On Tuesday, Microsoft issued security bulletin MS08-059 to address the vulnerability detailed in CVE- 2008-3466. In its patch bulletin, ranked as critical, Microsoft said "this vulnerability could allow remote code execution if an attacker sent a specially crafted remote procedure call request to an affected system. Customers who follow best practices and configure the systems network architecture remote procedure call (SNA RPC) service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights."

Apparently Microsoft knew of the exploit. To help system administrators prioritize the patches an "Exploitablity Index" was inaugurated with the October Patch Tuesday releases. Microsoft gave MS08-059 a 1 for having "for consistently functioning exploits". Other index ratings include 2 for "inconsistently functioning exploits" (of moderate concern), and 3 for vulnerabilities that are "unlikely to produce functioning exploits" (of least concern).

  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

Most Discussed



advertisement

Inside CNET News

Scroll Left Scroll Right