Slashdot Mirror


Microsoft Confirms Zero-Day Hours After Exploit

CWmike writes "Microsoft confirmed on Tuesday an unpatched vulnerability in Windows just hours after a hacking toolkit published an exploit for the bug. A patch is under construction, but Microsoft does not plan to issue an emergency update to fix the flaw. The bug was first discussed Dec. 15 at a South Korean security conference, but got more attention Tuesday when the open-source Metasploit penetration tool posted an exploit module crafted by researcher Joshua Drake. Metasploit says successful attacks are capable of compromising victimized PCs, then introducing malware to the machines to pillage them for information or enlist them in a criminal botnet."

5 of 53 comments (clear)

  1. Would it kill you to link to the Microsoft article by BBTaeKwonDo · · Score: 4, Informative
  2. Re:Bashfest by Microlith · · Score: 4, Informative

    Oh wait, this is a NEW bug. Not the one noted above. Silly me.

  3. Re:Bashfest by BBTaeKwonDo · · Score: 3, Informative

    That's a different exploit. The new one at http://www.microsoft.com/technet/security/advisory/2490606.mspx affects the graphics rendering engine, the one you linked to http://www.microsoft.com/technet/security/advisory/2488013.mspx refers to CSS.

  4. Non-Affected Software by BasharTeg · · Score: 4, Informative

    Non-Affected Software
    Windows 7 for 32-bit Systems
    Windows 7 for x64-based Systems
    Windows Server 2008 R2 for x64-based Systems
    Windows Server 2008 R2 for Itanium-based Systems

    1. Re:Non-Affected Software by Red+Flayer · · Score: 3, Informative

      My point was that MS hasn't bothered to hotfix it because it doesn't affect their latest-gen OSes... even though some of the OSes it DOES affect are not yet EOLed.

      Did you miss the part about this affecting OSes that are't yet EOLed (but will be in the next year or so)?

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai