New Microsoft Windows Security Threat Emerges
The appearance of "exploit code" for a flaw in two widely used versions of Windows makes attacks highly likely. Enterprises should immediately block the affected ports and patch the vulnerable systems. On 17 November 2003, media reports and security advisories indicated that exploit code designed to take advantage of a critical security vulnerability in Microsoft's Windows operating system is circulating on the Internet. The code exploits a buffer-overrun flaw in the Workstation Service feature, which is enabled by default in Windows 2000 and Windows XP. A patch for the vulnerability is available at www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-049.asp. |