|
-
October 27th, 2008, 12:20 PM
#20
There's a fairly low-key but worrying bit of malware exploiting this at the moment: http://voices.washingtonpost.com/sec...exploitin.html
Don't been fooled into thinking that a worm exploiting MS08-067 will be just like the ones we saw a few years ago - there are several different ways that a client could get infected with a dropper that will then go off to scan and exploit a network normally protected by a firewall. You could simply add the dropper as a module to a typical drive-by download attack, for example.
POC code has been around for a few days, it clearly is possible to exploit this and the patch has been pretty comprehensively reverse engineered by researchers (and presumably also the bad guys).
If you're running a corporate network, then you should assume that you will eventually get hit by an MS08-067 based worm despite any countermeasures that you have in place. So patch now.
Similar Threads
-
By mohaughn in forum Microsoft Security Discussions
Replies: 1
Last Post: August 9th, 2005, 07:37 PM
-
By Tiger Shark in forum Microsoft Security Discussions
Replies: 5
Last Post: January 14th, 2005, 08:47 PM
-
By mohaughn in forum Microsoft Security Discussions
Replies: 2
Last Post: October 13th, 2004, 04:31 AM
-
By spools.exe in forum Microsoft Security Discussions
Replies: 0
Last Post: September 15th, 2003, 09:47 PM
Tags for this Thread
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|