Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

October 10th, 2008, 11:36 GMT · By

Exploit Code for 6 Month Old Unpatched XP SP3 and Vista SP1 Vulnerability

SHARE:

Adjust text size:


Security
Enlarge picture
In mid-April 2008, Microsoft published an Advisory informing Windows users of a new vulnerability affecting its Windows server and client platforms, including Windows Vista Service Pack 1 and Windows XP Service Pack 3, but also Windows Server 2008 and Windows Server 2003. In the
past six months, the Redmond company did not by any means rush to resolve this vulnerability, and labeled it with only an Important severity rating, meaning that the Windows flaw can only “allow elevation of privilege from authenticated user to LocalSystem”.

“Exploit code has been published on the Internet for the vulnerability addressed by this Advisory. Our investigation has shown that it does not affect customers who have applied the workarounds listed in the Advisory,” revealed Bill Sisk, Microsoft Security Response Center Communications Manager.

So far, Microsoft has not provided a patch to address the security vulnerability, but via the Advisory, the company is offering a few mitigations for impacted customers to bulletproof themselves against potential attacks. In this regard, for IIS 7.0, users can specify a WPI for an application pool using the Command Line utility APPCMD.exe; specify a WPI for an application pool in IIS Manager; while for IIS 6.0, they can configure a Worker Process Identity (WPI) for an application pool in IIS to use a created account in IIS Manager and disable MSDTC, according to Microsoft.

“At this time, we are not aware of attacks attempting to use the vulnerability. We will continue to monitor the situation and post updates to the Advisory (...) as we become aware of any important new information,” Sisk added.

Microsoft advised that impacted customers turn to the mitigations available via the Advisory in order to render useless any attacks making use of the exploit code released in the wild. At the time of writing this article, the Redmond giant failed to reveal any plan for a security update to be offered in the future.

TELL US WHAT YOU THINK:

2,636 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Windows 7 UAC, the Evolution

Insight into Microsoft's Threat Modeling Bag of Tricks

Opera 9.6 Available for Download

Windows Security Health Agent and Validator for XP SP3 and Vista SP1

AJAX Evolution in Internet Explorer 8

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM