MS09-001 resolves three vulnerabilities in the SMB protocol implementation, two of them leading straight to unauthenticated, remote code execution (read: total ownership of affected systems on a first-come-first-serve basis) and a mere denial of service condition.
Before you start thinking that these are all bad things that may happen in your future and hence ignorable, take a moment to appreciate the facts.
All versions of Windows up to and including 7 are vulnerable in their unpatched state, firewalled systems may be spared yet corporate PC’s rarely are firewalled from one another – which would give a potential worm plenty of room to spread – and that, in fact, there is a rumour around the block that there may already be exploit code in the wild for one or more of these vulnerabilities.
Patch now. Nobody would benefit from two Downadup-sized epidemics in one month – except virus writers.
tags
Razvan Stoica is a journalist turned teacher turned publicist and technology evangelist. Recruited by Bitdefender in 2004 to add zest to the company's online presence.
View all postsApril 03, 2025
March 12, 2025
February 20, 2025
February 11, 2025