Critical Windows Flaw Patched, Explanations Ensue
Article by George Norman
On 24 Oct 2008
In an article posted the other day, we were announcing the fact that Microsoft will break the Update Tuesday cycle in order to address the MS08-067 security issue which affects several Windows-based operating systems. Now that the fix has been released and the users have patched their systems, it is time to see what all the fuss was about.

Bas Alberts from Immunity Security says that the flaw refers to the manner in which Windows Server handles RPC requests. If an attacker chooses to send malicious messages to a system running on Windows OS, the security flaws within Windows Server could allow that attacker to gain control of the machine. Do you know how much time it took Immunity Security researchers to come up with an exploit code? Just 120 minutes from the time the patch was released. They did not need any specific details; the clues within the patch were enough.

Advertising

Two things must be noted. The first one is that due to the nature of the flaw (RPC request), no user interaction is required in exploiting it. Secondly, the MS08-067 flaw which dates back to Windows NT also affects the brand spanking new Windows 7 (the Beta version of it). It does not affect it as badly as it would XP for example, but it does affect it, which for some is a worrisome matter.

This is what computer security specialist Dave Aitel has to say on the matter: “What a great bug! I'm not going to spoil the fun for people still working on it, but it's very cute, like a new puppy, or an angry toddler!” Now isn’t that a plastic description that will put things in perspective. The main question is this: How come it took Microsoft so long to find this bug? Was it that well hidden, or where they simply not looking?



Tags: Windows, Microsoft, Windows Vista, Windows Update
About the author: George Norman
George is a leading software reviewer at FindMySoft, he is pasionate about technology and he likes to write about IT news
You can follow him on Google+, Facebook or Twitter
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forward
By George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.
Related News
By George Norman on 08 Oct 2011
Communications Manager with Microsoft, Kristina Libby (pictured to the left), has recently made public a list of 10 ways you will know that when your child grows up, he or she will work for the Redmond-based software giant
By George Norman on 09 Dec 2011
As the proud owner of an Android-powered Galaxy S2, I have to say that there are plenty of fun and interesting apps out there to use. As large as the screen is on my Galaxy S2, I sometimes want something that’s bigger
By George Norman on 25 Nov 2011
Today, Friday the 25th of November, is Black Friday, the day when just about anyone who has something to sell puts it on sale, offers it to you at a discounted price. The same applies to Intego, company that specializes in providing security solutions for Mac.
By George Norman on 22 Nov 2011
If you’re thinking about getting a new smartphone, chances are that you’re considering getting and iPhone or an Android-powered device. There is a third alternative that most people forget about: you could get a Windows Phone
Advertising
Hot Software Updates
Top Downloads
Become A Fan!
Link To Us!
Critical Windows Flaw Patched, Explanations Ensue
HTML Linking Code