New Microsoft flaw exploits in the wild

By
Follow google news

A number of exploits for disclosed vulnerabilities Microsoft vulnerabilities were reported to be in the wild just hours after the company’s Patch Tuesday release.

By Wednesday afternoon, a handful of exploits were already in use, according to Johannes Ullrich of the SANS Internet Storm Center.


Ullrich reported that exploits for both MS06-24, a patch for a Windows Media Player flaw, and MS06-025, a routing and remote access service (RRAS) patch, were both released by a penetration testing vendor to customers.

An exploit for a flaw in Microsoft Word that allows remote code execution was available before the release of the patch, according to SANS, while two exploits for a SMB privilege escalation flaw were also released to the public.

DoS exploits for an IP source routing exploit were also released, according to SANS.

Microsoft released 12 patches for 21 flaws on Tuesday, its largest bulletin release in more than a year. Eight of the patches were deemed critical by Microsoft.

The Redmond, Wash., computing company also released three bulletins it called "important," and one patch for a "moderate" flaw.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

ServiceNow nears deal to buy cyber security startup

ServiceNow nears deal to buy cyber security startup

NSW Health clinicians "normalise" bypass of cyber security controls

NSW Health clinicians "normalise" bypass of cyber security controls

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Services Australia may get powers to rein in data breach exposure

Services Australia may get powers to rein in data breach exposure

Log In

  |  Forgot your password?