![]() |
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
| Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks. |
| |||||||
![]() |
| |
| | #1 (permalink) |
| Microsoft® Windows Vista™ Ultimate x64 SP2 Windows 7 7127 x64 | New patch and it isn't patch Tuesday Microsoft has released an out-of-band patch to fix an extremely critical worm hole that exposes Windows users to remote code execution attacks. The emergency update comes just one week after the regularly scheduled Patch Tuesday and follows the discovery of a targeted zero-day attack, Microsoft said in an advisory. The vulnerability is rated “critical” on Windows 2000, Windows XP and Windows Server 2003. On Windows Vista and Windows Server 2008, the flaw carries an “important” rating. From Microsoft’s critical MS08-067 bulletin: A remote code execution vulnerability exists in the Server service on Windows systems. The vulnerability is due to the service not properly handling specially crafted RPC requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system. Microsoft said it was aware of “limited, targeted attacks attempting to exploit the vulnerability” but the company did not provide any clues about the origin of the attacks or the target that was hit. There are no signs yet of public proof-of-concept code. According to the bulletin, there is a chance that the vulnerability could lead to a “wormable exploit.” The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code. It is possible that this vulnerability could be used in the crafting of a wormable exploit. Firewall best practices and standard default firewall configurations can help protect network resources from attacks that originate outside the enterprise perimeter. The vulnerable Windows Server service provides RPC support, file and print support, and named pipe sharing over the network. It is also used to allow the sharing of your local resources (such as disks and printers) so that other users on the network can access them. This is the first out-of-cycle patch from Microsoft since the fix for the animated cursor vulnerability in April 2007. It is the 67th bulletin from Redmond this year. |
My System Specs![]() |
![]() |
| Thread Tools | |
| |
Similar Threads | ||||
| Thread | Forum | |||
| Patch Tuesday heads-up: 8 bulletins, 5 critical | Vista News | |||
| Critical Windows Bug Fix on Patch Tuesday | System Security | |||
| Patch Tuesday nuked my network connection | Vista General | |||
| Patch Tuesday... 3 critical | Vista General | |||
| MS Patch Tuesday - Vista dinged again | Vista General | |||