As Attacks Escalate, Microsoft Ships Emergency Windows Patch
Microsoft has rushed out and emergency patch for all supported versions of Windows to cover a gaping -- and under attack -- security flaw in the way shortcuts are displayed by the operating system.
The out-of-band update, rated “critical,” comes less than 20 days after the discovery of a sophisticated malware attack that combined the Windows zero-day flaw with security problems in SCADA systems and used stolen signed drivers to bypass security software.
Copycat attackers also added exploits for the Windows vulnerability into malware families, putting pressure on Redmond to release today’s emergency fix.
From Microsoft’s MS10-046 bulletin:
The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
The flaw affects all currently supported versions of Windows XP, Vista, Windows 7, WindowsServer 2008 and Windows Server 2008 R2.
Recommended Reads
Commenting on this Article is closed.
Today's Most Popular
Most Commented Stories
-
Mac OS X Sandbox Security Hole Uncovered (6)
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (6)
-
Flash With Sandbox in the Works for Firefox (4)
-
Anonymous Leaks FBI, Scotland Yard Phone Call Detailing Hacking Investigations (6)
-
Privacy Fail: Is Uncle Sam Encouraging Bad Security? (8)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




