This just in from our ‘friends’ at Slashdot – a critical Microsoft patch for all “modern” Windows systems.
There’s a bulletin notice located here which is pretty alarming, from the bulletin:
“This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request.”
“On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code.”
This isn’t the first time we’ve seen an RPC vulnerability, the most memorable one I can recall was Blaster which caused a great deal of havoc.
I’d suggest applying the security update when it is released…