Huge Increase Seen in Attacks on Windows Help Center Flaw
Attackers are ramping up their attempts to exploit the recently disclosed vulnerability in the Windows Help and Support Center in Windows XP. There have been targeted attacks against the flaw for two weeks now, but experts have noticed a major increase in the volume and spread of them in recent days.
Microsoft's security group has been looking at data coming back from machines running the company's anti-malware software, as well as from other data sources, and found that attacks against the Windows Help and Support Center flaw have been increasing dramatically over the last few days. Since the first targeted attacks against the vulnerability began in mid-June, the volume and diversity of exploitation attempts has been on the rise, Microsoft said.
According to Microsoft's data on the attack, more than 10,000 unique machines have seen this attack at least once. And that data obviously isn't comprehensive, as it typically just includes data sent back from PCs running Microsoft's security software. But the company added that the attacks also have been widely distributed around world, with the U.S., Russia, Germany and a few other countries seeing the most attacks so far.
Windows Help and Support Center Attacks
The company said that most of the original attacks included one payload, a piece of malware called Obitel that serves as a downloader for subsequent malware installations. But the current wave of attacks has a number of different payloads, including a couple of Trojan downloaders that end up on victim machines after several script redirections.
Microsoft has released a FixIt tool for the Windows Help and Support Center flaw, a weakness that also affects Windows Server 2003. The company has not yet released a patch for the vulnerability, which was disclosed in early June.
Commenting on this Article is closed.
Today's Most Popular
- Yahoo Includes Private Key in Source File For Axis Chrome Extension
- Researchers Unveil New Way to Trust Certificates
- FBI Warns Top Firms Of Anonymous Protest Hacks on May 25
- DNSChanger Lingers: 330k Systems Still Infected, 77,000 In The U.S.
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (10)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (14)
-
FBI Warns Top Firms Of Anonymous Protest Hacks on May 25 (2)
-
Facebook Cancellation Malware Disguised As Adobe Update Making Rounds (3)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



