That was fast: Microsoft bug already exploited

Opinion
Oct 27, 20082 mins

* Attack code for critical Microsoft bug surfaces * Patches from FreeBSD, Debian, Ubuntu

Hope you’ve got that out-of-cycle Windows patch installed, because there’s already a worm running amok exploiting the flaw. Microsoft took the unusual step of rushing out a patch for Windows last Thursday and within hours attack code was published that could take advantage of the flaw. Not quite Zero Day, but pretty close. Of course, a lot of noise was made over Microsoft’s non-Patch Tuesday release, but some in the security community are wondering what the big deal is? After all, there are automatic systems in place to install said patches, and other vendors release patches all the time without a parade. So why the hoopla over this Microsoft release?

Attack code for critical Microsoft bug surfaces

Just hours after Microsoft posted details of a critical Windows bug, new attack code that exploits the flaw has surfaced. It took developers of the Immunity security testing tool two hours to write their exploit, after Microsoft released a patch for the issue Thursday morning. IDG News Service, 10/23/2008.

Also:

Data-Stealing Trojan Exploiting Just-Patched Windows Flaw

Microsoft says Windows flaw could bring worm attack

Microsoft advisory: Vulnerability in Server Service Could Allow Remote Code Execution

**********

FreeBSD patches IPv6 issue

A vulnerability in FreeBSD’s Neighbor Discovery protocol, part of its IPv6 implementation, could be exploited by an attacker to update router configurations without authorization. An update is available.

**********

Debian releases fix for libspf2 flaw

Dan Kaminski, the guy who figured out the major flaw in DNS this past summer, has found a buffer overflow vulnerability in libspf2, an implemenation of the Sender Policy Framework that is used by mail servers to filter for Spam and other bad messages. An attacker could exploit the flaw to run malicious code. An update is available.

**********

Two new updates from Ubuntu:

Moodle (code execution)

Amarok (race condition, file overwrite)