New Microsoft flaw exploits in the wild

By
Follow google news

A number of exploits for disclosed vulnerabilities Microsoft vulnerabilities were reported to be in the wild just hours after the company’s Patch Tuesday release.

By Wednesday afternoon, a handful of exploits were already in use, according to Johannes Ullrich of the SANS Internet Storm Center.


Ullrich reported that exploits for both MS06-24, a patch for a Windows Media Player flaw, and MS06-025, a routing and remote access service (RRAS) patch, were both released by a penetration testing vendor to customers.

An exploit for a flaw in Microsoft Word that allows remote code execution was available before the release of the patch, according to SANS, while two exploits for a SMB privilege escalation flaw were also released to the public.

DoS exploits for an IP source routing exploit were also released, according to SANS.

Microsoft released 12 patches for 21 flaws on Tuesday, its largest bulletin release in more than a year. Eight of the patches were deemed critical by Microsoft.

The Redmond, Wash., computing company also released three bulletins it called "important," and one patch for a "moderate" flaw.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?