Unpatched Windows XP-related hole exploited in attacks


Recommended Posts

Unpatched Windows XP-related hole exploited in attacks

"We want to reiterate that customers using Windows 2000, Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2 are not affected. Additionally, Windows Server 2003 customers are not at risk based on the attack samples we have analyzed," he said. "We encourage Windows XP customers to install the workaround provided in the advisory via a Microsoft FixIt. We continue to monitor the threat landscape and will keep customers updated via our blog at http://blogs.technet.com/b/msrc and our Twitter handle, www.twitter.com/msftsecresponse."

The vulnerability, which is in the online Windows Help and Support Center, could enable an attacker to take control of a computer running Windows XP by luring a computer user to a malicious Web site hosting code that exploits the hole, regardless of what browser is being used.

Earlier on Tuesday, Sophos reported seeing exploits in the wild on its blog. Sophos' software detects the exploit as Troj/Drop-FS and offers a free threat detection scan and information for how to remove the Trojan.

More details - http://news.cnet.com/security/

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...