Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Windows 7 and Server 2008 R2 - SMB denial of service attack exploit

Storm A denial-of-service creates an endless loop where PCs or servers become unresponsive. The Windows 7 security system will prevent malware infections to the system itself for this specific attack.  An infected system could lock up and require rebooting if an attack were successful.

These attacks may spike to 100% CPU utilitzation or be overwhelmed with intense network traffic.  Windows 7 and Server 2008 R2 and users should keep autoupdates enabled and monitor developments for a forthcoming patch.  Keeping your firewall enabled and AV protection in place also provides protection for current unpatched systems.

Windows 7 and Server 2008 R2 - SMB denial of service attack exploit
http://www.microsoft.com/technet/security/advisory/977544.mspx
http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx
http://isc.sans.org/diary.html?storyid=7597
http://isc.sans.org/diary.html?storyid=7573

QUOTE: this is a DoS vulnerability that is unrelated to Microsoft Security Bulletin MS09-050 which addressed a remote code execution vulnerability in the SMBv2 protocol. This vulnerability would not allow an attacker to take control or install malware on a user’s system, but could cause the affected system to stop responding until manually restarted.

MSRC - Excellent site to monitor further developments
http://blogs.technet.com/msrc/