NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Microsoft Reacts to Windows 7 0-Day DoS Vulnerability

Publishes Security Advisory 977544

By Marius Oiaga, Technology News Editor

14th of November 2009, 12:04 GMT

Adjust text size:


Windows 7
Enlarge picture
Microsoft has reacted rapidly to public reports of a zero-day denial-of-service vulnerability in its latest iterations of the Windows client and server operating systems, and is providing customers with guidance on how to block potential attempts to take advantage of the security flaw. In this regard, the Redmond company has underlined that no exploits or attacks have been detected for the denial-of-service (DoS) hole in the Microsoft Server Message Block (SMB) Protocol impacting both SMBv1 and SMBv2 in Windows 7 and Windows Server 2008 R2. However, Proof of Concept (PoC) code was irresponsibly published in the wild, making it extremely easy for attackers to build exploits putting at risk users of Windows 7.

“Microsoft is aware of public, detailed exploit code that would cause a system to stop functioning or become unreliable. If exploited, this DoS vulnerability would not allow an attacker to take control of, or install malware on, the customer’s system but could cause the affected system to stop responding until manually restarted. It is important to note that the default firewall settings on Windows 7 will help block attempts to exploit this issue,” Dave Forstrom, group manager, public relations, Microsoft Trustworthy Computing, revealed. “The company is not aware of attacks to exploit the reported vulnerability at this time.”

Users currently running Windows 7 and Windows Server 2008 R2 need to know that Microsoft published Security Advisory 977544, in response to the details available in the wild of the DoS vulnerability. The advisory contains a section titled Workarounds, which advices Windows 7 customers to block TCP ports 139 and 445 at the firewall in order to bulletproof their systems against potential attacks.

“While Microsoft is not currently aware of active attacks, the company recommends customers review and implement the workarounds outlined in the advisory until a comprehensive security update is released,” Forstrom explained. Microsoft confirmed that the vulnerability was Windows 7-specific and that users running Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and Windows 2000 were not affected.

TAGS:

Windows 7 | RTM | DoS | PoC | 0-day
Read by 3,109 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.4/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Xbox LIVE Update Drops November 17, 2009

Office Starter 2010 Beta Invitations Sent to Testers

Windows 7 Beta Bots Caused the Build 7000 Availability Delay

Download SQL Server 2008 R2 November CTP

Zero-Day Windows 7 RTM DoS Vulnerability Has PoC Published in the Wild

Windows Live Adds YouTube as Feed Partner

Free Microsoft Security Tool Fights Rogues Masquerading as Windows Security Solutions

Componentized and Embedded Windows 7 CTP2 Coming in the Next Month

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM