Sep 11 2003

Yet another Microsoft vulnerability

Published by Martin at 7:30 am under Microsoft

Microsoft does it again! Yes, they have revealed yet another RPC/DCOM vulnerability. This one is exploitable through port 80, since it is RPC over HTTP. What comes next? And to add insult to injury, this vulnerability is different enought from MS03-026 that you have to install a seperate patch and test to see how many of your applications this on breaks.

Microsoft has said that the RPC service are an intergal part of Windows and you can’t live without it. But a number people are shutting down the vulnerable services and finding that very few programs really rely on RPC/DCOM. As time allows, I will be researching this some on my own and finding out what breaks when you disable RPC. What gets me is that even the folks at Microsoft don’t fully understand the ramifications of this service.

Add this to my Crystal Ball list of exploits worthy of their own worm in the next 4-6 weeks. And I’m not the only one predicting the a new round of worms. Not that these predictions are all that hard to make. Can someone pass me the Tylenol? Or, as a coworker suggested, the Vodka.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Comments are closed at this time.