1/24/2008

Windows Small Business Server at risk from critical flaw

Filed under: — By Aviran Mordo @ 12:21 pm

Microsoft said Wednesday that another one of its operating system products is vulnerable to a critical vulnerability, first patched two weeks ago.

In an update to its MS08-001 security bulletin, Microsoft said that the latest release of Windows Small Business Server was also critically at risk from a bug in Windows’ networking software.

The flaw is also considered critical for Windows XP and Vista users. Microsoft did not say why it had initially omitted Small Business Server from its list of critically affected operating systems, but it said that the product’s users were being offered patches via Microsoft’s various automatic update services. “Customers with Windows Small Business Server 2003 Service Pack 2 should apply the update to remain secure,” Microsoft said in its updated bulletin.

The bug lies in the way Windows processes networking traffic that uses IGMP (Internet Group Management Protocol) and MLD (Multicast Listener Discovery) protocols, which are used to send data to many systems at the same time. Microsoft said that an attacker could send specially crafted packets to a victim’s machine, which could then allow the attacker to run unauthorized code on a system.

Microsoft rates the flaw as “important” for Windows Server 2003, meaning that it would be more difficult for attackers to exploit the flaw on this operating system.

Security experts are paying particular attention to this vulnerability because it could be exploited by attackers to create a self-replicating worm attack.

 

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress