• Apple
  • Vulnerabilities
  • Microsoft Windows Phone 7
  • Google
  • Virtualisation
  • Windows XP
  • WGA / Windows Genuine Advantage
  • Battery
  • LED
  • Gaming
  • Microsoft Windows 7 Hit By Zero Day Vulnerability


    15 November, 2009, by Desire Athow

    Laurence Gaffié, a security researcher, has discovered a weakness in Windows 7 and published all the relevant details on the full disclosure mailing list archives at Insecure.org.

    The bug has been recognised by Microsoft but its importance has been minimised by the software company. On his blog, Gaffié went as far as providing with a proof of concept which he used to remotely crash Windows 7 (and Windows Server 2008 R2) on a local area network.

    Such an attack is also possible through any version of Internet Explorer even older ones (or broadcasting NetBIOS Name Server "trick") even if the system's firewall is activated. The vulnerability, which is found in the Server Message Block (SMB) file sharing protocol, could effectively be used to perform a denial of service (DOS) attack through an infinite loop.

    Canada-based Gaffié also maintains that the bug was a "real proof" that Microsoft's Security Development Lifecycle had failed. The temporary solution, according to him would be to, "Close SMB feature and ports, until a real audit is provided." However, the flaw doesn't allow hackers to gain unauthorised remote access to information on any machine.

    Article continues after advert

    Microsoft has rapidly released a security advisory and suggests that two ports at the firewall could be blocked to protect users from any external attacks. Older versions of Windows, Vista, Server 2008 R1, Server 2003, Windows 2000 and Windows XP are not affected by the bug.

    Continued on next page Tags: Microsoft, Windows, Windows 7, Windows 7 Home Premium, Windows 7 Ultimate
    Desire Athow
    Posted by
    Desire Athow
    on 15 November, 2009

    Désiré Athow is the Content Editor of ITProPortal.com and has been reporting on technology and telecommunication since 1999. You can follow him on Twitter.
    ITProPortal.com - Sponsored Section

    Featured Content

    1. The New Voice of the CIO. 158 CIOs in midsized businesses across 31 countries reveal their insights and vision for enhancing competitiveness over the next five years.

      Download Document

    Customer Case Studies

    1. How a wine wholesaler improved the flow of information
      Download full case study
    2. The server that made an entire university smarter
      Download full case study

    Videos

    Connecting in a smarter planet:

    Latest Tweets





     





    News Now Logo




    Forgot your password?