Critical Windows Flaw Patched, Explanations Ensue
Article by George Norman
On 24 Oct 2008
In an article posted the other day, we were announcing the fact that Microsoft will break the Update Tuesday cycle in order to address the MS08-067 security issue which affects several Windows-based operating systems. Now that the fix has been released and the users have patched their systems, it is time to see what all the fuss was about.

Bas Alberts from Immunity Security says that the flaw refers to the manner in which Windows Server handles RPC requests. If an attacker chooses to send malicious messages to a system running on Windows OS, the security flaws within Windows Server could allow that attacker to gain control of the machine. Do you know how much time it took Immunity Security researchers to come up with an exploit code? Just 120 minutes from the time the patch was released. They did not need any specific details; the clues within the patch were enough.

Advertising

Two things must be noted. The first one is that due to the nature of the flaw (RPC request), no user interaction is required in exploiting it. Secondly, the MS08-067 flaw which dates back to Windows NT also affects the brand spanking new Windows 7 (the Beta version of it). It does not affect it as badly as it would XP for example, but it does affect it, which for some is a worrisome matter.

This is what computer security specialist Dave Aitel has to say on the matter: “What a great bug! I'm not going to spoil the fun for people still working on it, but it's very cute, like a new puppy, or an angry toddler!” Now isn’t that a plastic description that will put things in perspective. The main question is this: How come it took Microsoft so long to find this bug? Was it that well hidden, or where they simply not looking?



Tags: Windows, Microsoft, Windows Vista, Windows Update
About the author: George Norman
George is a news editor.
You can follow him on Google+, Facebook or Twitter

I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 24 Feb 2017
In all, a total of 56 games spread across 24 award categories were nominated for the 20th Annual D.I.C.E. Awards by the Academy of Interactive Arts & Sciences (AIAS), the non-profit organization dedicated to the advancement and recognition of the interactive arts.
By George Norman on 24 Feb 2017
Looking for something to play this weekend but you don’t want to purchase anything? You’re in luck, because Steam’s giving you the change to play these three games for free.
Related News
By George Norman on 07 Oct 2016
Right out of the box, BitTorrent offers a pretty enjoyable user experience. There’s room for improvement though, and all you have to do is turn off a few settings that are enabled by default.
By George Norman on 26 Sep 2016
The thing that annoys me about Windows Photo Viewer is that the background color isn’t black. Not by default anyway. But with a bit of tinkering, it can easily be changed to black.
By George Norman on 23 Sep 2016
With the release of version 3.0, nearly everything about TunnelBear has been improved. But the thing that will strike you most is the redesigned, brand new interface.
By George Norman on 05 Sep 2016
Google recently updated Chrome for desktop and, among other things, tweaked the web browser’s interface so that it is in line with the company’s Material Design philosophy.
Sponsored Links
Hot Software Updates
Top Downloads
Become A Fan!
Link To Us!
Critical Windows Flaw Patched, Explanations Ensue
HTML Linking Code