Solution Builder - Channel Insider
 
 

A Progress Report on Windows' ASN.1 Vulnerability


Article Rating:starstarstarstarstar / 0

Rate This Article:
Add This Article To:
It's too soon to tell if Windows users have dodged a bullet from Microsoft's recently-disclosed and most egregious vulnerability: ASN.1. The current assessment looks as if things could be worse.

On February 10, Microsoft disclosed a dangerous vulnerability in all modern versions of Windows, along with a patch to fix it. Nine days may not seem like a long time, but every day that goes by without a real exploit is great news.

Click here for Microsoft's advisory and links to the patches)

At the same time, there is an exploit out in the wild that performs a distributed denial-of-service by crashing the attacked system. DDoS attacks are a bad thing, of course, but they aren't as much of a worry from a mass-attack standpoint. Authors can't make a worm out of a DDoS attack because if the system crashes, there's scant opportunity to trick the owner into spreading the worm.

A real worm requires a means of infection and the ability to execute arbitrary code on the infected system. The Microsoft advisory indicates that this is possible with the ASN.1 issue.

There have been allegations that the claim of arbitrary code execution is an exaggeration, however, experts advised me that a code execution worm is merely difficult, but not impossible. Given a large number of vulnerable systems in the world, such a worm could still spread.

To read the full story, click here.





Discuss A Progress Report on Windows' ASN.1 Vulnerability
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Solution Builder Articles          >>> More By Larry Seltzer
 


 

Vizard: IBM Gets Principled About the Channel
Big Blue looks to improve its reputation with a Principles of Engagement document governing how internal salespeople deal with the channel.

CHANNEL DEEP DIVES
CareersLinux and Unix
Computer NetworkingPrinters
SecuritySMB Partner
StorageSurveys
Solution BuilderMessaging/Collaboration
Dell ResellersMicrosoft Partners

SIGN UP FOR CHANNEL INSIDER NEWSLETTERS
Reliable, timely information on the business of technology. Sign up now.


 

CHANNEL RESOURCE CENTER
HP StorageWorks Scalable NAS is highly available, scalable network-attached storage for any industry solution. To learn how you can take full advantage of fault-tolerant NAS that seamlessly scales capacity and performance, visit: http://www.hp.com/go/scalablenas


Feature Video: What Can Green Do For You?
There are many ways that systems can be run faster or more efficiently, using less energy and thereby reducing costs. Watch now!
Microsoft-hosted solution offers you advanced customer relationship management capabilities without a major investment in IT and staffing.
Try It for free for 30 days!