Microsoft rushes out quick fix for SMB flaw

 

Issue affects Vista and Windows Server 2008 users.

Microsoft has raced to ship a one-off workaround for the Server Message Block (SMB) v2 vulnerability disclosed earlier this week, in order to mitigate the risk of users’ Vista or Windows Server 2008 products being hacked.

The one-click fix, which was added to a Microsoft security advisory, has been designed to provide users’ machines with temporary respite from any remote code execution attacks targeting the known vulnerability, by disabling SMBv2 and then stopping and starting the Server service.

However, Redmond warned that disabling SMBv2 may slow down SMB connections between Windows Vista and Windows Server 2008 machines.

The firm also confirmed that the exploit code developed for the vulnerability by penetration testing firm Immunity does indeed work. “It works reliably against 32-bit Windows Vista and Windows Server 2008 systems,” said Microsoft in a posting on its Security Research and Defense blog.

"The exploit gains complete control of the targeted system and can be launched by an unauthenticated user.”

As with other security issues brought to light by researchers, such as the disclosure of IIS vulnerabilities recently, Microsoft is again holding the line that customers may have been put at unnecessary risk by the irresponsible way such vulnerabilities were disclosed.

“We continue to encourage responsible disclosure of vulnerabilities,” wrote the firm in its accompanying security advisory.

“We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests.”

Copyright ©v3.co.uk


Microsoft rushes out quick fix for SMB flaw
"Microsoft would have let this problem drag on unpatched for weeks if their hand wasn't forced by this so-called "irresponsible disclosure" of the vulnerability. I am bemused by Microsoft ..."
By HyRax
 
 
 
Comments: 1
HyRax
Sep 21, 2009 8:42 AM
Microsoft would have let this problem drag on unpatched for weeks if their hand wasn't forced by this so-called "irresponsible disclosure" of the vulnerability.

I am bemused by Microsoft seemingly more concerned about people not USING the protocol rather than just get around to fixing the problem, saying it would slow down SMB connections between workstation and server. Spin all the way. They are so afraid that people will stop using it en-masse...
Comments have been disabled for this article.
 
 
 
Top Stories
Vito Forte: A CIO for tough times
Fortescue Metals CIO talks vendor management and innovation.
 
Tech staff spared in ANZ's 1000 job cuts
Cost cutting hits middle management.
 
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  83%
 
No
  17%
TOTAL VOTES: 245

Vote