Windows News and info 15th Anniversary 2009-2024

Other Operating Systems => Windows Server 2025 => Topic started by: riso on July 02, 2010, 04:43:58 PM

Title: Over 10,000 XP machines attacked by unpatched vulnerability
Post by: riso on July 02, 2010, 04:43:58 PM
(http://www.blogcdn.com/www.engadget.com/media/2010/03/xp-20100302.jpg)
Users of Windows XP may want to double down on security until Microsoft deals with a recently identified flaw (CVE-2010-1885). A Google engineer found the hole last month and at first, Microsoft said it only saw "legitimate researchers testing innocuous proof-of-concepts" – but it didn't take long for malicious hackers to prey on the vulnerability.

The hole apparently lies in the Windows Help and Support Center software that is included with Windows XP. Attackers are using various methods to take advantage of the bug, and payloads vary greatly. Microsoft has released a list of some of the payloads detected so far. Most are Trojans, and you can find the list toward the end of this blog post.
Quote
http://blogs.technet.com/b/mmpc/archive/2010/06/30/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885.aspx
To date, Microsoft believes over 10,000 separate machines have been attacked at least once by means of the flaw. Those systems are scattered all around the globe, with attacks logged in about 20 countries. The largest number of attacks are taking place in Portugal and Russia – about ten times the global average (where the US sits), to be precise.

According to the security advisory posted for CVE-2010-1885, Windows XP SP2 and SP3, Windows XP Professional x64 SP2, Windows Server 2003 SP2, Windows Server 2003 x64 SP2, and Windows Server 2003 with SP2 for Itanium-based systems are all affected. However, in the executive summary, Microsoft says Windows Server 2003 systems are not currently at risk.

The company is working on a fix and may release an out-of-band patch, but until then, users can use a one-click Fix-It tool to disable the Help Center.
Quote
http://support.microsoft.com/kb/2219475

You can also delete HPC manually by following the brief instructions posted under "Workarounds" on the Security Advisory page, and be sure to create a backup as directed.
Quote
http://www.microsoft.com/technet/security/advisory/2219475.mspx
Title: Re: Over 10,000 XP machines attacked by unpatched vulnerability
Post by: Jake on July 02, 2010, 09:52:21 PM
Hooray!!


Oh I mean uhh... oh no!

 ;)
Title: Re: Over 10,000 XP machines attacked by unpatched vulnerability
Post by: javajolt on July 02, 2010, 11:45:38 PM

Irtehpasty, I can just see you dancing in the streets!  :D  :D
Title: Re: Over 10,000 XP machines attacked by unpatched vulnerability
Post by: Jake on July 03, 2010, 02:17:12 AM

Irtehpasty, I can just see you dancing in the streets!  :D  :D

I can feel the burning desire of IT departments to upgrade, it's about time