SHARE
Facebook X Pinterest WhatsApp

A Progress Report on Windows’ ASN.1 Vulnerability

On February 10, Microsoft disclosed a dangerous vulnerability in all modern versions of Windows, along with a patch to fix it. Nine days may not seem like a long time, but every day that goes by without a real exploit is great news. Click here for Microsoft’s advisory and links to the patches) At the […]

Written By: Larry Seltzer
Feb 20, 2004
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

On February 10, Microsoft disclosed a dangerous vulnerability in all modern versions of Windows, along with a patch to fix it. Nine days may not seem like a long time, but every day that goes by without a real exploit is great news.

Click here for Microsoft’s advisory and links to the patches)

At the same time, there is an exploit out in the wild that performs a distributed denial-of-service by crashing the attacked system. DDoS attacks are a bad thing, of course, but they aren’t as much of a worry from a mass-attack standpoint. Authors can’t make a worm out of a DDoS attack because if the system crashes, there’s scant opportunity to trick the owner into spreading the worm.

A real worm requires a means of infection and the ability to execute arbitrary code on the infected system. The Microsoft advisory indicates that this is possible with the ASN.1 issue.

There have been allegations that the claim of arbitrary code execution is an exaggeration, however, experts advised me that a code execution worm is merely difficult, but not impossible. Given a large number of vulnerable systems in the world, such a worm could still spread.

To read the full story, click here.

Recommended for you...

June Roundup: M&A Moves Across the Shifting Channel Landscape
Jordan Smith
Jul 7, 2025
Leadership Roundup: New CEOs Highlight June Moves
Jordan Smith
Jul 2, 2025
Workspan AI Looks to Solve Channel Ecosystem Complexity
Victoria Durgin
Jun 25, 2025
May Roundup: Mergers and Acquisitions From Around the Channel
Jordan Smith
Jun 2, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.