eWeek Security Watch
Advertisement
Advertisement
November 16, 2006 7:43 PM

The Exploits Are A-Comin'



windows_patch.jpg As expected, the exploits for this week's Patch Day flaws are coming fast and furious, including at least two for the nasty MS06-070 worm hole. If you are in charge of a Windows 2000 shop, there's no excuse to delay patch deployment for this one.

At Milw0rm, "cocoruder" has posted a remote exploit that's been successfully tested on Windows 2000 Server SP4 (Chinese).

Customers in Dave Aitel's Immunity Partner Program also have access to a fully-functional exploit for the MS06-070 bug.

It's a testament to the times we live in when exploits can be written and networks can be scanned for vulnerable hosts ten times faster than patches can be tested and deployed.

UPDATE: Ken Dunham, director of Verisign's iDefense Rapid Response Team sent this nugget via e-mail:

"iDefense has discovered that hackers originally discovered this the MS06-070 vulnerability a year ago but had initial difficulty in using it to trigger execution of code."

According to eEye, Microsoft shipped the patch 122 days after the flaw was reported on July 25, 2006.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/9719

Post a Comment

 
 
RSS Syndication
Advertisement

CAG

SEO

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise