Remote exploit released for Windows Vista SMB2 worm hole
Security researchers at penetration testing firm Immunity have created a reliable remote exploit capable of spawning a worm through an unpatched security hole in Microsoft's dominant Windows operating system.
A team of exploit writers led by Kostya Kortchinsky attacked the known SMB v2 vulnerability and created a remote exploit that's been fitted into Immunity's Canvas pen-testing platform. The exploit hits all versions of Windows Vista and Windows Server 2008 SP2, according to Immunity's Dave Aitel.
[ SEE: Microsoft Confirms SMB2 Flaw, Heightens Severity ]
Immunity's Canvas is used by IDS (intrusion detection companies) and larger penetrating testing firms as a risk management tool.
Exploit writers at the freely available Metasploit Project are also close to finishing a reliable exploit for the vulnerability, according to Metasploit's HD Moore.
Editor's Pick
The vulnerability, which was originally released as a denial-of-service issue, does not affect the RTM version of Windows 7, Microsoft said. It appears Microsoft fixed the flaw in Windows 7 build ~7130, just after RC1. Windows Vista and Windows Server 2008 users remain at risk.
In the absence of patch, Microsoft recommends that users disable SMB v2 and block TCP ports 139 and 445 at the firewall.
* Hat tip: Dan Goodin/The Register.
Commenting on this Article is closed.
Today's Most Popular
- DHS Warns About Threat Of Mobile Devices In Healthcare
- Another Cybersecurity Bill Runs Into Trouble on Capitol Hill
- Hijacked Web Sites Among The Most Visited On Google's Black List
- Like Those Wikipedia Ads? They Mean You're Infected With Malware!
- Senator Seeks More Info On DOJ Location Tracking Practices
Most Commented Stories
-
Facebook Open to Comments on Proposed Privacy Policy Changes (5)
-
Adobe Reverses Course, Plans Free Updates for Illustrator, Photoshop, Flash Professional (4)
-
Spammers Targeting Pinterest Using Point-And-Click Tools (1)
-
FBI Concerned About Bitcoin Usage Among Cybercriminals (4)
-
Another Cybersecurity Bill Runs Into Trouble on Capitol Hill (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




