Samker's Computer Forum - SCforum.info

World TOP Headlines: => Latest Security News & Alerts => Topic started by: Samker on 14. November 2009., 09:45:23

Title: Microsoft probing Windows 7 zero-day hole (SMB - Server Message Block)
Post by: Samker on 14. November 2009., 09:45:23
(http://i.i.com.com/cnwk.1d/i/zd-fd/0609/img_hm_new-win-logo.jpg)

Microsoft said on Wednesday it is looking into a report of a vulnerability in Windows 7 and Server 2008 Release 2 that could be used by an attacker to remotely crash the computer.

The company is investigating claims of a "possible denial-of-service vulnerability in Windows Server Message Block (SMB)," the Microsoft spokesperson said, adding that the company was unaware of any attacks trying to exploit the hole.

The bug triggers an infinite loop on the Server Message Block (SMB) protocol used for sharing files in Windows, researcher Laurent Gaffié wrote in a posting on the Full-Disclosure mailing list: http://seclists.org/fulldisclosure/2009/Nov/134 (http://seclists.org/fulldisclosure/2009/Nov/134) and on a blog: http://g-laurent.blogspot.com/2009/11/windows-7-server-2008r2-remote-kernel.html (http://g-laurent.blogspot.com/2009/11/windows-7-server-2008r2-remote-kernel.html)

"Whatever your firewall is set to, you can get remotely smashed via IE or even via some broadcasting NBNS [NetBIOS Naming Service] tricks," Gaffié wrote.

Gaffié also posted proof-of-concept code for the "Windows 7, Server 2008R2 Remote Kernel Crash."

On Tuesday, Microsoft issued six patches to fix 15 vulnerabilities, including a critical hole in the Windows kernel, as part of November's Patch Tuesday.

(Cnet)