Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

November 29th, 2006, 15:05 GMT · By

New Worm - Old Vulnerabilities

SHARE:

Adjust text size:


Symantec has warned of the discovery of W32.Spybot.ACYR, a new worm that targets an array of old vulnerabilities dating as far back as July 16, 2003. Spybot.ACYR is designed to exploit
a number of seven vulnerabilities, five in Microsoft products, one in Symantec products and one Multiple Vendor FTPD realpath Vulnerability.

The following vulnerabilities are associated with Microsoft products:

- The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026)
- The Microsoft Windows Message Queuing Remote Buffer Overflow Vulnerability (as described in Microsoft Security Bullettin MS05-017)
- The Microsoft ASN.1 Library Multiple Stack-Based Buffer Overflow vulnerabilities (as described in Microsoft Security Bulletin MS04-007)
- The Microsoft Windows Plug and Play Buffer Overflow Vulnerability (as described in Microsoft Security Bullettin MS05-017)
- The Microsoft Windows Server Service Remote Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS06-040)

In fact, users of unpatched versions of Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP are vulnerable to attacks.

Additionally, vulnerabilities in Symantec Client Security and Symantec AnitVirus Elevation of privilege are also a vector for the worm's spreading alongside network shares protected by weak passwords.

"At the present time, we are seeing a spike in traffic on Port 2967 with activity only in the .edu domain. Based on Symantec's intelligence, the impact of the attack is minimal thus far. Detection for W32.Spybot.ACY is available through rapid release sequence #61675 as W32.Spybot.Worm, but this has been subsequently renamed to W32.Spybot.ACYR. Certified definitions for this worm are scheduled for release on Tuesday, November 28, 2006," revealed Symantec.

Updating the software you are deploying accordingly will protect you against this threat. Another mitigating factor could be the blocking of Port 2967 at your firewall.

TELL US WHAT YOU THINK:

8,873 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Symantec: Security Threat Is Gearing Toward Electronic Transactions

Backup Exec 11d for Windows Servers Software

Symantec Announces Mobile AntiVirus 4.0 for Windows Mobile

How to Handle Vulnerabilities

Will Symantec's Security FOR Vista Work WITH Vista?

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM