<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; oob patch</title>
	<atom:link href="http://www.darknet.org.uk/tag/oob-patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft Confirms Windows Zero Day Bug In Shortcut Files</title>
		<link>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/</link>
		<comments>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 09:51:55 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0-day windows exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[windows shortcut exploit]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows xp sp2]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2804</guid>
		<description><![CDATA[This is a pretty nasty attack and for once Microsoft have actually acknowledged and confirmed this is a critical unpatched vulnerability. Incidentally Microsoft also recently retired Windows XP SP2 from the support cycle, and this vulnerability effects that system and they have stated they will not be patching it. It&#8217;s a pretty serious bug and [...]]]></description>
			<content:encoded><![CDATA[<p>This is a pretty nasty attack and for once <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> have actually acknowledged and confirmed this is a critical unpatched vulnerability. Incidentally Microsoft also recently retired Windows XP SP2 from the support cycle, and this vulnerability effects that system and they have stated they will not be patching it.</p>
<p>It&#8217;s a pretty serious bug and it seems hackers have been maliciously exploiting it in the wild for over a month. The Stuxnet malware has been using this vulnerability to gain access to machines then download further attack files including a <a href="http://www.darknet.org.uk/tag/root-kit/">root kit</a>.</p>
<blockquote><p>Microsoft on Friday warned that attackers are exploiting a critical unpatched Windows vulnerability using infected USB flash drives.</p>
<p>The bug admission is the first that affects Windows XP Service Pack 2 (SP2) since Microsoft retired the edition from support , researchers said. When Microsoft does fix the flaw, it will not be providing a patch for machines still running XP SP2. In a security advisory , Microsoft confirmed what other researchers had been saying for almost a month: Hackers have been exploiting a bug in Windows &#8220;shortcut&#8221; files, the placeholders typically dropped on the desktop or into the Start menu to represent links to actual files or programs.</p>
<p>&#8220;In the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware,&#8221; Dave Forstrom, a director in Microsoft&#8217;s Trustworthy Computing group, said in a post Friday to a company blog . Stuxnet is a clan of malware that includes a Trojan horse that downloads further attack code, including a rootkit that hides evidence of the attack.</p>
<p>Forstrom characterized the threat as &#8220;limited, targeted attacks,&#8221; but the Microsoft group responsible for crafting antivirus signatures said it had tracked 6,000 attempts to infect Windows PCs as of July 15. </p></blockquote>
<p>Limited but targeted attacks are the worst kind as they can really burrow through corporate defenses. A lot of companies are taking this seriously, including all the main players in the anti-virus arena.</p>
<p>You have to wonder if Microsoft will break their <a href="http://www.darknet.org.uk/tag/patch-tuesday/">patch tuesday</a> policy and issue an emergency <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-band patch</a> for this.</p>
<p>Especially since <a href="http://www.networkworld.com/news/2010/072310-virus-writers-are-picking-up.html?source=nww_rss">more virus writers are picking up on this flaw</a> meaning it&#8217;s becoming more widespread.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<blockquote><p>On Friday, Siemens alerted customers of its Simatic WinCC management software that attacks using the Windows vulnerability were targeting computers used to manage large-scale industrial control systems used by major manufacturing and utility companies. The vulnerability was first mentioned on June 17 in an alert issued by VirusBlokAda , a little-known security firm based in Belarus. Other security organizations, including U.K.-based Sophos and SANS Institute&#8217;s Internet Storm Center , picked up on the threat Friday. Security blogger Brian Krebs , formerly with the Washington Post, reported on it Thursday.</p>
<p>According to Microsoft, Windows fails to correctly parse shortcut files, identified by the &#8220;.lnk&#8221; extension. The flaw has been exploited most frequently using USB flash drives. By crafting a malicious .lnk file, hackers can hijack a Windows PC with little user interaction: All that&#8217;s necessary is that the user views the contents of the USB drive with a file manager like Windows Explorer.</p>
<p>Chester Wisniewski, a senior security advisory with Sophos, called the threat &#8220;nasty,&#8221; and said his tests showed that the exploit works even when AutoRun and AutoPlay &#8212; two functions that have previously been used by attackers to commandeer PCs using infected flash drives &#8212; are disabled. The rootkit also bypasses all security mechanisms in Windows, including the User Account Control (UAC) prompts in Vista and Windows 7 , said Wisniewski in a blog entry Friday. </p></blockquote>
<p>I&#8217;m sure they&#8217;ll come up with some reason for not patching this sooner rather than later. The scary part is the attack can still be carried out even if AutoRun and AutoPlay are disabled.</p>
<p>The rootkit also bypasses the security mechanisms in Windows 7 and Vista making this a very dangerous attack.</p>
<p>You can find a temporary workaround in the Microsoft Security Advisory here:</p>
<p><a href="http://support.microsoft.com/kb/2286198">Microsoft Security Advisory: Vulnerability in Windows Shell could allow remote code execution</a></p>
<p>And Microsoft has stated they are working on a patch.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/071710-microsoft-confirms-nasty-windows-zero-day.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2804+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;t=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Fmicrosoft-confirms-windows-zero-day-bug-in-shortcut-files%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Releases Out-Of-Band Patch For IE 0-Day Vulnerability</title>
		<link>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 08:01:14 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[crc-16]]></category>
		<category><![CDATA[data execution prevention]]></category>
		<category><![CDATA[dep]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking-IE]]></category>
		<category><![CDATA[ie 0day]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[IE-security]]></category>
		<category><![CDATA[IE-vulnerability]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet explorere 0day]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch tuesday]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2457</guid>
		<description><![CDATA[Ah Microsoft is treating this one seriously after France and Germany advised users to avoid IE. The current strain being exploited only targets IE6 users, but one security company has developed an exploit for IE8 which also bypasses DEP (Data Execution Prevention). It was rumoured this was the exploit used last week to compromise Google [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> is treating this one seriously after <a href="http://www.eweek.com/c/a/Security/France-Germany-Say-Avoid-IE-Until-Security-Vulnerability-Patched-321481/">France and Germany advised users to avoid IE</a>.</p>
<p>The current strain being exploited only targets IE6 users, but one security company has developed an exploit for IE8 which also bypasses DEP (Data Execution Prevention).</p>
<p>It was rumoured this was the exploit used last week to compromise Google and various other high profile networks. Although I am skeptical as to why anyone was using IE inside Google? Perhaps doing cross browser testing for development, who knows.</p>
<blockquote><p>Microsoft will release an out-of-band patch Jan. 21 to fix the Internet Explorer vulnerability at the center of recent attacks on Google and other enterprises.</p>
<p>According to Microsoft, the patch is slated to be ready around 1 p.m. EST. If all goes according to plan, the patch will close a hole that has prompted France and Germany to advise users to avoid IE and the U.S. State Department to demand answers from China. Attackers have used the vulnerability to hit IE 6. Microsoft so far has said it has only seen limited, targeted attacks using the vulnerability.</p>
<p>Meanwhile, security researchers have continued to uncover information about the origin of the attack. Joe Stewart, director of malware research for SecureWorks&#8217; Counter Threat Unit, said his analysis of the code for the main Trojan involved in the attacks shows a more direct link to China. </p></blockquote>
<p>It&#8217;s very rare for them to push an <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-band patch</a> for anything but I guess there are still a LOT of IE users out there and this is a serious flaw.</p>
<p>It does seem to originate from China with the only discussions about the technical parts of the flaw and implementation being discussed on Chinese language sites.</p>
<p>As can be seen by a Google search here (<a href="http://www.google.com/search?q="crc_ta[16]"&#038;ie=utf-8&#038;oe=utf-8&#038;aq=t&#038;rls=org.mozilla:en-US:official&#038;client=firefox-a">&#8220;crc_ta[16]&#8220;</a>), after the first few English news sites reporting the flaw the rest of the results are in Chinese.</p>
<blockquote><p>According to Stewart, the code includes a CRC (cyclic redundancy check) algorithm implementation released as part of a Chinese-language paper on optimizing CRC algorithms for use in microcontrollers.</p>
<p>&#8220;This CRC -16 implementation seems to be virtually unknown outside of China, as shown by a Google search for one of the key variables, &#8216;crc_ta[16],&#8217;&#8221; Stewart noted in a SecureWorks blog post Jan. 20. &#8220;At the time of this writing, almost every page with meaningful content concerning the algorithm is Chinese.&#8221;</p>
<p>Up until this finding, Stewart told eWEEK, the factors leading people to point to China were patterns similar to previous Chinese malware.</p>
<p>&#8220;Unfortunately, when investigating malware, nothing is conclusive because digital evidence can be forged,&#8221; he said. &#8220;However, I believe the use of the Chinese algorithm certainly gives more credence to the attack code being Chinese in origin.&#8221;</p></blockquote>
<p>They really have no choice but to release this patch when faced with government pressure, you should see it hitting your Windows Update sometime today (Jan 21st).</p>
<p>Let&#8217;s hope this patch has been tested properly and doesn&#8217;t subject users to another <a href="http://www.darknet.org.uk/2009/12/microsoft-leaves-users-waiting-for-black-screen-of-death-fix/">black screen of death</a>.</p>
<p>It&#8217;s good to see some proactive initiatives by Microsoft, I hope they continue through 2010.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Microsoft-IE-Patch-for-ZeroDay-Vulnerability-Coming-Tomorrow-804909/">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2457+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;t=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Fmicrosoft-releases-out-of-band-patch-for-ie-0-day-vulnerability%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Rushes Out Critical RPC Bug Fix</title>
		<link>http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/</link>
		<comments>http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 09:37:01 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[rpc bug]]></category>
		<category><![CDATA[rpc flaw]]></category>
		<category><![CDATA[rpc vulnerability]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows vulnerbility]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1175</guid>
		<description><![CDATA[Now this doesn&#8217;t happen all that often, it must be really serious! An Out-of-Band patch from Microsoft (since it&#8217;s famous &#8216;Patch Tuesday&#8216; it only releases patches on the second Tuesday of each month) has been released for a new RPC flaw. I&#8217;d imagine it&#8217;s similar to the RPC flaw that spawned such disasters as Blaster [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Now this doesn&#8217;t happen all that often, it must be really serious! An Out-of-Band patch from Microsoft (since it&#8217;s famous &#8216;<em><a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a></em>&#8216; it only releases patches on the second Tuesday of each month) has been released for a new RPC flaw.</p>
<p>I&#8217;d imagine it&#8217;s similar to the RPC flaw that spawned such disasters as Blaster and Sasser in 2003/4.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">Microsoft Security Bulletin MS08-067 – Critical</a></p>
<blockquote><p>Microsoft has released an emergency security update for a broad swath of its users that patches a critical security hole that is already being exploited in the wild.</p>
<p>The vulnerability &#8211; which has been subjected to &#8220;limited, targeted attacks&#8221; &#8211; could allow miscreants to create wormable exploits that remotely execute malicious code on vulnerable machines, Microsoft said. No interaction is required from the end user. It was the first patch released outside Microsoft&#8217;s regular update cycle in 18 months.</p>
<p>&#8220;This is a remote code execution vulnerability,&#8221; Microsoft&#8217;s out-of-band advisory warned. &#8220;An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely.&#8221;</p></blockquote>
<p>There is an active piece of malware in the wild using this, F-secure has already detected it and has a signature for <a href="http://www.f-secure.com/weblog/archives/00001519.html">Trojan-Spy:W32/Gimmiv.A</a>.</p>
<p>This may have been running around in the wild for some time, perhaps in the underground community. There are always true remote exploits that are unknown to the mass community used by certain higher level groups.</p>
<blockquote><p>This is the sixth time Microsoft has issued and out-of-band security update since October 2004 when it implemented its policy of releasing patches on the second Tuesday of each month, a company spokesman said. The last time an unscheduled patch update was issued was in April 2007 when it moved to fix a critical bug in the ANI animated cursor feature of Windows.</p>
<p>Thursday&#8217;s bulletin also marked the second time Microsoft has offered additional vulnerability details to security providers in advance. About an hour before the patch was released publicly, members of the Microsoft Active Protections Program (MAPP) received a briefing that allowed them to create signatures that detect exploits in anti-virus software and intrusion prevention systems.</p>
<p>Microsoft also offered a stunning amount of detail about the vulnerability to regular Joes <a href="http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx">here</a>.</p></blockquote>
<p>It&#8217;s only the 6th time this has happened since October 2004 (around 4 years) so you can see that it&#8217;s serious and you better install it across any networks you administer.</p>
<p>The update will require a reboot (as usual..).</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/10/23/emergency_windows_update/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Rushes+Out+Critical+RPC+Bug+Fix+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1175+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/&amp;t=Microsoft+Rushes+Out+Critical+RPC+Bug+Fix" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/&amp;title=Microsoft+Rushes+Out+Critical+RPC+Bug+Fix" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/&amp;title=Microsoft+Rushes+Out+Critical+RPC+Bug+Fix" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/&amp;title=Microsoft+Rushes+Out+Critical+RPC+Bug+Fix" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/&amp;title=Microsoft+Rushes+Out+Critical+RPC+Bug+Fix" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F10%2Fmicrosoft-rushes-out-critical-rpc-bug-fix%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/10/microsoft-rushes-out-critical-rpc-bug-fix/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

