Subscribe to Windows IT Pro
November 03, 2008 12:00 AM

As Expected: New Worm Exploits Latest Windows Hole

Windows IT Pro
InstantDoc ID #100692
Rating: (0)

As usually happens, only days after Microsoft publish its advisory regarding a serious problem with RPC a worm was unleashed to exploit the vulnerability.

The advisory, MS08-067, indicates that the vulnerability exists in Windows 2000, XP, Server 2003, and Vista. So far the worm is known to work against Windows 2000, Windows XP, and Windows Server 2003. However that could change at any second.

According to Symantec the worm drops itself into place, creates a couple of necessary registry keys, deletes the cached copy of the Server service DLL, attempts to download 2 files from various remote servers, reports its IP to another remote server, then proceeds to attempt to spread itself to other systems on the local network.

F-Secure reported that they were seeing the first signs of worm code last week. That particular code tries to add the Guest account to the Administrators group. Obviously not a good thing.

I hope your systems are patched.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.