NEWS Microsoft has warned customers that a security hole in Windows 2000 and the company's web server software is allowing online attackers to take control of corporate servers - but the warning comes too late for the US army whose web servers have already fallen victim to the flaw. Because the vulnerability is already being actively exploited by internet vandals, Microsoft advised customers to apply a patch or use a workaround to defend against the attack as soon as possible. Iain Mulholland, security program manager for Microsoft's security response centre, said: "We have had isolated reports from customers that [the flaw] is getting exploited. We have issued a number of workaround options. Ultimately, the only way to protect yourself is to apply a patch." The incident embodies a worst-case scenario for how a vulnerability should be discovered. Companies generally hope that researchers will discover a flaw, inform the software maker, and then wait to announce the flaw once a patch is prepared. When online vandals have access to a 'zero day' vulnerability - a flaw that companies aren't warned of - they can break into far more computers before software makers understand what is going on. Microsoft learned of the vulnerability after online hackers used the flaw to breach the security of a customer's web servers last Wednesday, Mulholland said. He said the incident is being investigated by federal law enforcement. Atlanta-based Internet Security Systems also had a customer affected and confirmed that a tool to take advantage of the flaw is being distributed on the internet. Still, attacks are not yet widespread, said Dan Ingevaldson, team leader for Internet Security Systems' research and development group. "We have sensors that are deployed all over the world, and we have not seen them light up with this attack," he said. "So we believe the incidents are contained at this point, but we don't expect that to last very long." The flaw, known as a buffer overflow, is in a component of the software that handles the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol in Microsoft's Internet Information Server (IIS). A specially formatted web request to the WebDAV component can overflow the memory allocated to such requests and cause another, malicious program to be run instead. The technique can be used to take control of the server. The flaw affects only IIS 5.0 on Windows 2000 servers. IIS 4.0 on Windows NT and IIS 5.1 on Windows XP are not affected. How quickly the patch and workarounds get applied is a big question for the software giant. In the past, system administrators have been slow to apply the software fixes. Patches released six months before the Slammer worm didn't prevent that malicious program from spreading to nearly 200,000 Microsoft SQL servers. This time around, the company doesn't have a head start on those abusing the flaw. Whether that threat spurs companies to apply the patches more quickly remains to be seen.
Microsoft warns of 'zero day' vulnerability
It's already caught the US army out... don't be next...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




