Microsoft looking into new SMB vulnerability report

Powered by SC Magazine
 

Investigation begins at Redmond.

Microsoft is investigating a researcher's claim that the software giant's newest operating system contains a vulnerability that could be exploited to crash systems.

Researcher Laurent Gaffie published proof-of-concept code that allows an attacker to exploit a vulnerability in Windows 7 and Server 2008 Release 2.

The flaw, detailed by Gaffie in a blog post last week, lies in the Windows Server Message Block (SMB) and requires no user interaction to exploit.

Attackers can remotely crash systems if a victim machine receives malformed packets, Jonathan Leopando, a member of the Trend Micro technical communications team, said in a blog post.

"Whatever your firewall is set to, you can get remotely smashed via IE (Internet Explorer) or even via some NBNS (NetBios Name Service) tricks," Gaffie said.

Christopher Budd, security response communications lead at Microsoft, said in a statement that the software giant is aware of the purported vulnerability, which is said to cause a denial-of-service attack.

"We're currently unaware of any attacks trying to use the claimed vulnerability or of customer impact," Budd said. "Once we're done investigating, we will take appropriate action to help protect customers."

Users are encouraged to block ports used by the SMB protocol until Microsoft offers workarounds or permanent fix,  Leopando said.

In October, Microsoft patched another serious vulnerability in the SMB protocol that Gaffie discovered.

See original article on scmagazineus.com

Copyright © SC Magazine, US edition


 
 
 
Top Stories
Making a case for collaboration
[Blog post] Tap into your company’s people power.
 
Five zero-cost ways to improve MySQL performance
How to easily boost MySQL throughput by up to 5x.
 
Tracking the year of CIO churn
[Blog post] Who shone through in 12 months of disruption?
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
This 4G smartphone costs $219
Sep 3, 2014
It's possible to spend a lot less on a smartphone if you're prepared to go with a brand you ...
Looking for storage? Seagate has five new small business NAS devices
Aug 22, 2014
Seagate has announced a new portfolio of Networked Attached Storage (NAS) solutions specifically ...
Run a small business in western Sydney?
Aug 15, 2014
This event might be of interest if you're looking to meet other people with a similar interest ...
Buying a tablet? Microsoft's Surface Pro 3 goes on sale this month
Aug 8, 2014
Microsoft has announced its Surface Pro 3 will go on sale in Australia on 28 August from ...
Apple's top MacBook Pro with Retina is now cheaper
Aug 1, 2014
Apple has updated its MacBook Pro range with faster processors and new pricing, including ...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  69%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  10%
 
Denial of service attacks
  6%
 
Insider threats
  11%
TOTAL VOTES: 1086

Vote