Microsoft releases patches for leaked, wormable 'SMBGhost' flaw

By
Follow google news

Marcus Hutchins of WannaCry fame releases proof of concept.

Microsoft has rushed out security updates for a remotely exploitable vulnerability in the Windows System Message Block version 3 file sharing protocol that researchers said could be abused to create self-spreading "worms" like the 2017 WannaCry malware.

Microsoft releases patches for leaked, wormable 'SMBGhost' flaw
Source: Marcus Hutchins.

After leaking information this week of the vulnerability as part of its regular Patch Wednesday round of updates to security vendors who published details about it, Microsoft was only able to  provide a partial workaround for the critical flaw for Server operating systems.

Windows clients with SMBv3 remained vulnerable to exploitation.

Updates for Windows 10 32 and 64-bit systems and Windows Server are now available from  Microsoft, which it strongly recommends users to install them as soon as possible.

Security researchers noted that the vulnerability, known as EternalDarkness and SMBGhost as it doesn't require authentication by attackers, could be used to create self-replicating malware, so-called worms.

Kryptos Logic security researcher, Briton Marcus Hutchins who rose to fame during the 2017 WannaCry worm epidemic that cost vast financial damage, analysed the flaw and found it to be similar to the earlier Remote Desktop Protocol DejaBlue one.

DejaBlue along with another wormable flaw, Bluekeep, were discovered last year and Microsoft issued patches for them in September.

Hutchins has written a proof of concept script for CVE-2020-0796 that can be used to generate denial of service attacks on vulnerable systems.

His employer Kryptos Logic scanned the internet and found some 48,000 vulnerable hosts exposing the SMBv3 protocol to the world.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Qld gov says students, staff caught in Canvas cyber incident

Qld gov says students, staff caught in Canvas cyber incident

Aus universities and TAFEs investigating exposure to Canvas cyber incident

Aus universities and TAFEs investigating exposure to Canvas cyber incident

Log In

  |  Forgot your password?