Welcome | Log In
Malware

Microsoft Under Pressure to Deliver Zero-Day DNS Patch

Print Version
E-Mail Article
Reprints

Redmond said it will release a fix to a critical Windows DNS flaw that opens a hole for phishing attacks and other e-mail disruptions, but no date has been set. Security experts warned of an increased number of attacks after the code for at least four of the exploits was published on the Web last weekend.


Verio MPS Solutions
Verio managed server solutions deliver the power and flexibility of a dedicated server at a fraction of the price. Learn more about how Verio gives you increased control, scalability, uptime, and performance.

Microsoft (Nasdaq: MSFT) More about Microsoft on Wednesday announced plans to offer a fix to a critical flaw in Windows Consolidate Mac Servers. Run Windows Server on your Mac. Watch a Demo or Download a Trial. Domain Name System (DNS) servers that is currently being exploited by cybercriminals.

The zero-day flaw, found on servers running Windows Server 2000 Service Pack 4 and Windows Server 2003 Service Pack 1 and Service Pack 2, gives attackers full control over infected computers via an Internet Relay Chat channel.

The public release of computer code that exploits the yet-to-be-patched Windows security hole has put pressure on Redmond to release a patch prior to its next patch cycle on May 8.

The flaw opens a hole for phishing attacks, directory services problems and other types of e-mail disruptions, according to Microsoft.

Widespread Exploit

Security experts are warning that at least four exploits of the DNS flaw were published on the Internet last weekend, raising concerns over the possibility of widespread attacks.

Once the code was published, Symantec (Nasdaq: SYMC) More about Symantec raised its risk level and warned of an expected increase in attacks.

On Monday, security experts revealed that variants of the Rinbot (or Nirbot) worm had been scanning networks for vulnerable systems and then attempting to exploit the DNS vulnerability.

Limited Attack Cited

Microsoft last week reported a "limited attack" on systems due to the flaw, but that was before the exploit's code was widely published on the Web.

"We are aware, though, of public disclosure of proof-of-concept code to exploit the vulnerability," Christopher Budd, a Microsoft Security Response Center spokesperson, wrote on the company's security blog.

"Attacks are still limited," he added.

Users of vulnerable systems should apply the workarounds that are available on Microsoft's security bulletin page.

Fast-Moving Worm

Although the publication of the code has raised alarms in many quarters, properly protected servers should not be vulnerable, according to security vendor Sophos More about Sophos.

The flaw in Microsoft's code may have been around for a only a few days, but it didn't take long for hackers to take advantage of it, Graham Cluley, senior technology consultant for Sophos, told TechNewsWorld.

"Time and time again, hackers are forcing companies like Microsoft to scramble around to develop, test and roll out a software patch," Cluley noted.

Keeping Watch

Although Microsoft has not provided an estimate of when the fix will be ready for download, its teams around the world are "working on it 24 hours a day," according to Budd.

"However, this is a developing situation and we are constantly evaluating the situation and the status of our development and testing of updates," Budd said in his blog.

The DNS breach is the latest in a recent string of security flaws affecting Microsoft's software.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Tim Gray   RSS

Related Resources

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
  WiFi Hotspot Locator
City or Zip/Postal Code:
Country/Region:
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network