Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Forums > Vista News

Vista - New flaw can crash Windows Vista and Server 2008 remotely (Updated)

Reply
 
Old 09-08-2009   #1 (permalink)


Vista Ultimate 64-bit, SP2
 
 

New flaw can crash Windows Vista and Server 2008 remotely (Updated)

By Emil Protalinski.

Redmond is investigating reports that a newly discovered flaw in Microsoft's implementation of the Server Message Block 2 (SMB2) protocol, an extension of the conventional server message block protocol, can be exploited to remotely crash and restart computers running Windows Vista or Windows 7. The attack does not require authentication, but port 445 of the target system must be open, and on Windows it is open by default. Laurent Gaffié, who discovered the vulnerability, has contacted Microsoft, noting that the only solution he can think of is to turn off the SMB feature and close port 445.

Article link -
New flaw can crash Windows Vista and Server 2008 remotely (Updated) - Ars Technica

My System SpecsSystem Spec
Old 09-09-2009   #2 (permalink)


Vista Home Premium 32bit [x86] - SP2
 
 

Re: Microsoft Security Response Centre; MS Security Advisory 975497 Released.

MSRC have released details of Security Advisory 975497, here;


The Microsoft Security Response Center (MSRC) : Microsoft Security Advisory 975497 Released

...and expanded further with details of;

Microsoft Security Advisory (975497); Vulnerabilities in Microsoft SMB (Server Message Block) Could Allow Remote Code Execution.

This advisory is detailed, with information about affected and unaffected software. This is an extract from the advisory, of some of the affected software;

Affected Software; Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2

Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2

Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2

The advisory also has extensive information on workarounds for the vulnerability. It is stressed that the workarounds do not provide a solution for the issue, but can afford some interim security by helping to block known attack sources, before an update to fix the problem, is issued. These details can be read by clicking onto "Advisory 975497" in the first sentence of the advisory.

Last edited by sassofalco; 09-09-2009 at 01:52 AM.. Reason: Links were not linking
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Error when installing SQL Express 2008 on Windows Server 2008 PowerShell
Vista RDP to Windows 2008 Server Vista General
Windows Server 2008 hosted on Virtual Server 2005 R2 very slow Virtual Server
Windows 2008 Server and Vista - Just FYI Vista General
Bug: Windows Modules Service Is Broken In Windows Server 2008 Beta 3 Web Server Addition. Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46