Tech

Guides
 

Microsoft probing Windows 7 zero-day hole

By Elinor Mills, CNET News.com
Thursday, November 12, 2009 11:40 AM

Microsoft said on Wednesday it is looking into a report of a vulnerability in Windows 7 and Server 2008 Release 2 that could be used by an attacker to remotely crash the computer.

The company is investigating claims of a "possible denial-of-service vulnerability in Windows Server Message Block (SMB)", the Microsoft spokesperson said, adding that the company was unaware of any attacks trying to exploit the hole.

The bug triggers an infinite loop on the Server Message Block (SMB) protocol used for sharing files in Windows, researcher Laurent Gaffié; wrote in a posting on the Full-Disclosure mailing list and on a blog.

"Whatever your firewall is set to, you can get remotely smashed via IE or even via some broadcasting NBNS [NetBIOS Naming Service] tricks," Gaffié wrote.

Gaffié also posted proof-of-concept code for the "Windows 7, Server 2008R2 Remote Kernel Crash".

This week, Microsoft issued six patches to fix 15 vulnerabilities, including a critical hole in the Windows kernel, as part of November's Patch Tuesday.

This article was first published as a blog post on CNET News.



WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Whitepapers/Case Studies

Downloads

SMB News



Tech Jobs Now!

Tags

  1. bank
  2. banking
  3. banking industry
  4. business applications
  5. business strategies & functions
  6. china
  7. cio
  8. clinician
  9. customer
  10. data management
  11. data warehousing / business intelligence
  12. database
  13. emr
  14. financial
  15. industry
  16. information technology
  17. innovation
  18. it budgeting
  19. leadership
  20. technology