Microsoft: Flaw could lead to worm attack
Microsoft has fixed a critical flaw in the Windows operating system that could
be used by criminals to create a self-copying computer worm attack.
The software vendor released its first set of patches for 2008 on Tuesday,
fixing a pair of networking flaws in the Windows kernel. Microsoft
also released a second update for a less-serious Windows flaw that would allow
attackers to steal passwords or run Windows software with elevated privileges.
The critical bug lies in the way Windows processes networking traffic that uses IGMP (Internet Group Management Protocol) and MLD (Multicast Listener Discovery) protocols, which are used to send data to many systems at the same time. Microsoft says that an attacker could send specially crafted packets to a victim's machine, which could then allow the attacker to run unauthorized code on a system.
Security experts say that there is no known code that exploits this flaw, but
now that the patch has been posted, hackers can reverse-engineer the fix and
develop their own attack code.
Because IGMP is enabled in Windows XP and Vista by default, this bug could
be used to create a self-copying worm attack, Microsoft said Tuesday.
"Theoretically this is wormable and that's why this is rated critical,"
said Tim Rains, security response communications lead with Microsoft. However,
Microsoft does not believe that hackers will have an easy time developing attack
code that will work reliably. "We've done a thorough analysis of the vulnerability
and we've come to the conclusion that there are several technical mitigating
factors that make it unlikely to get reliable remote code execution," Rains
said.
Windows uses the IGMP protocol for many popular consumer applications such
as streaming video, multiplayer games and universal plug-and-play, but the protocol
is usually blocked at the router. A derivative of IGMP, MLD is the multicast
protocol used by IPv6 systems and is enabled on Vista by default
"If it became a worm it could take over an internal network pretty quickly,
or at least all the machines where multicast is enabled," said Eric Schultze,
chief technology officer with Shavlik
Technologies. "But this one is going to be mitigated because a lot
of people have blocked multicast."
The critical MS08-001
update that fixes this flaw also patches a second, less-serious bug in the Windows
networking stack that could be leveraged to launch a denial of service attack
against a Windows system. This vulnerability lies in the Internet Control Message
Protocol Router Discovery Protocol (ICMP RDP) which is used by Windows to find
out how to communicate with the network. Because this capability is not turned
on by default, Microsoft considers this to be merely an "important"
bug.
Microsoft's other Tuesday update, MS08-002,
fixes an elevation of privilege flaw in the Windows Local Security Authority
Subsystem Service (LSASS), used to manage account credentials in Windows.
This flaw could be exploited by attackers to steal passwords or run their code
with a higher level of privilege on Windows, said Schultze. "The primary
concern is Johnny who is a user becoming Johnny admin," he said. But if
attackers were to combine an attack that exploited this flaw with another exploit
that would allow them to run code on the system, then "that could become
a critical issue," he said.
IDG News Service
Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.
Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.
Crimeware: Understanding New Attacks and Defenses
By Markus Jakobsson, Zulfikar Ramzan
Published Apr 6, 2008 by Addison-Wesley Professional. Part of the Symantec Press series.
Enter now! | Official rules | Sample chapter
Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures
By Peter Thermos, Ari Takanen
Published Aug 1, 2007 by Addison-Wesley Professional.
Enter now! | Official rules | Sample chapter







