Microsoft Host Integration Server Flaw ExploitedMicrosoft Host Integration Server Flaw Exploited
A new code was last week posted on the Internet that could exploit a flaw in unpatched Microsoft Host Integration Servers.
The exploit is part of Metasploit, a toolkit used by penetration testers and criminal hackers alike.
Recently, microsoft issued security bulletin MS08-059 to address the
vulnerability detailed in CVE- 2008-3466. In its patch bulletin, ranked
as critical, Microsoft said "this vulnerability could allow remote code
execution if an attacker sent a specially crafted remote procedure call
request to an affected system. Customers who follow best practices and
configure the systems network architecture remote procedure call (SNA
RPC) service account to have fewer user rights on the system could be
less impacted than customers who configure the SNA RPC service account
to have administrative user rights."
Apparently, Microsoft knew of the exploit. To help system
administrators prioritize the patches an "Exploitablity Index" was
inaugurated with the October Patch releases. Microsoft gave MS08-059 a
1 for having "for consistently functioning exploits". Other index
ratings include 2 for "inconsistently functioning exploits" (of
moderate concern), and 3 for vulnerabilities that are "unlikely to
produce functioning exploits" (of least concern).
|