Worm feasts on latest Windows vuln
Ooh Betty, it's happening again
Posted in Malware, 14th August 2006 14:35 GMT
Free whitepaper – Out-of-box comparison between Dell, HP, and IBM blade servers
Virus writers have adapted an existing family of worms to exploit a recently patched, high-profile Windows security vulnerability.
Corporate admins are being are urged to redouble their efforts to roll out security patches as quickly as possible.
The Cuebot-L and Cuebot-M worms spread via AOL instant messenger, exploiting the MS06-040 vulnerability in Windows Server Service.
If successful, the latest variants of the worm turn off security controls in the Windows firewall and open a backdoor onto compromised machines, allowing hackers to remotely control machines, which thereafter become zombie clients in botnet networks.
Previous versions of the worm caused two earlier Windows vulnerabilities to spread, as explained in an advisory by CA here.
Microsoft last week released a "critical" patch for the Windows server flaw exploited by Cuebot-L and Cuebot-M. Security experts were quick to see its potential for exploitation, now realised with the Cuebot-L and Cuebot-M worms.
The Department of Homeland Security took the unusual step of warning of the seriousness of the flaw shortly after Redmond's release of the corresponding software fix. ®

Analyst Keynote: The Register Agile Data Center Summit
Enabling The Agile Data Center
Breaching Fort Apache.org - What went wrong?
Snow Leopard security - The good, the bad and the missing
US Dems fill inboxes with 419 scams
BlockMaster SafeStick hardware-encrypted USB drive