You are here: silicon.com > Hardware > Servers

Servers

Windows flaw jeopardises millions of PCs and servers

Think Code Red, think Nimda...

By Robert Lemos

Published: 21 November 2002 08:40 GMT

A software bug in a common component of Microsoft web servers and Internet Explorer could leave millions of servers and home PCs open to attack.

The vulnerability, found by security company Foundstone and confirmed by Microsoft, could allow an internet attacker to take over a web server, spread an email virus or create a fast-spreading network worm.

George Kurtz, CEO of Foundstone, said: "There are millions of systems and clients that will be affected by this."

Foundstone originally discovered the flaw and worked with Microsoft to develop a patch.

The flaw, in a component of Windows that allows web servers and browsers to communicate with online databases, could be as widespread as the flaws that allowed the Code Red and Nimda worms to spread, said Kurtz.

More than 4.1 million sites hosted on Microsoft's Internet Information Service (IIS) software are likely to be affected. In addition, millions of Windows 95, 98, Me and 2000 PCs could also be vulnerable to the software bug.

Microsoft rated the flaw as critical, and Lynn Terwoerds, security program manager for Microsoft's security response centre, said: "There is a possibility that it might be wormable, it is clearly critical. We want the patch uptake to be really high."

Visit http://www.microsoft.com/technet for more information on how to protect yourself against this flaw.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Seb Janacek Minority Report: Mac Mini - a real nowhere machine What could it have become with a little more love and attention?

Bethan Jones Can I use a netbook as my everyday work machine? Part II silicon.com sub editor reveals whether her netbook delivered


  • Jobs
Windows, .NET Implementation Support Engineer

Work with the development team to deliver final solutions into the production environment Liaise with the development team to resolve any problems ...

Technical Analyst - SMS, SCCM, WSUS - Patch & Release

The role will involve the assessment of vulnerabilities, patch testing and application deployment via remote systems such as SMS/SCCM, WSUS and ...

Patch/Release Technical Specialist - Pathc Testing - SMS/SCCM

Patch/Release Technical Specialist - Patch Testing - SMS/SCCMExperienced Patch/Release Specialist required to join a high profile blue chip solutions ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: