Exploit code raises Windows worm alarm

October 14, 2005

 

Exploit code raises Windows worm alarm | CNET News.com: "Exploit code exists for four of the 14 vulnerabilities for which Microsoft provided fixes this week, experts said Thursday. One of the exploits was written for a flaw which Microsoft tagged as 'critical.' The bug lies in a Windows component for transaction processing called the Microsoft Distributed Transaction Coordinator, or MSDTC.

'When we start to see exploits surfacing, we know there will shortly be malicious code,' said Alfred Huger, a senior director at Symantec Security Response. 'We expect at least the MSDTC vulnerability to be used in a worm in the short term.'"

It's sorta hard to decipher all the hype from reality.. Yes, in the past few years we've seen several examples of MS vulnerablilities turn into some nasty worms, but lately I've been seeing a news article like this after every major patch release, which just turns out to be all hype. I'm not willing to bet my networks and systems on wheter or not this is hype, but unfortunately I fear many will.

0 comments: