Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Microsoft issues emergency security patch MS08-067

Microsoft issues emergency security patch MS08-067

PATCH NOW
-- This is especially true if you use XP as there might be a potential for WORMABLE exploits to develop that can take over vulnerable PCs without any user actions (as most exploits require a mouse click or other action)  Blaster and Sasser are examples of past worms that could infect vulnerable systems by simply connecting them to the Internet.  Thankfully, there are no exploits like this currently circulating, but if there's a hole in the roof one should not wait for it to rain.  Hopefully, these concerns won't materialize and it's important to always stay up-to-date on security updates.

Microsoft issues emergency security patch MS08-067
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

QUOTE: This security update resolves a vulnerability in the Server service that affects all currently supported versions of Windows. Windows XP and older versions are rated as “Critical” while Windows Vista and newer versions are rated as “Important”. Because the vulnerability is potentially wormable on those older versions of Windows, we’re encouraging customers to test and deploy the update as soon as possible.

His biggest fear, he said, is that a worm will be developed to take over vulnerable machines en masse. And he fully expects that to happen. "You're talking about a vulnerability that does not need user interaction," he said. "That's a gold mine if you're trying to build a botnet."

Additional articles and information

http://isc.sans.org/diary.html?storyid=5227
http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=211600270
http://blogs.technet.com/msrc/archive/2008/10/23/ms08-067-released.aspx