Welcome to The UltraTech Zone Sign in | Join | Help

Talking Out Loud with ASB

Views on Life, Technology and Everything, by ASB (aka Logik!)...

News


Revenge of the Worms?

It's been a while since we've had a massive worm outbreak, but with word that a wormable exploit has been made available for the recent .

Microsoft has issued several status updates over the past few days via the , including the news that (which is one week shy of the normal patch release day).

Because of the criticality of this vulnerability and the various editions of Windows that it affects (including ), it is highly advisable that every effort be made to test and deploy the patch as soon as it becomes available tomorrow.   Other mitigation efforts include the following:

  • Reading email in plaintext (especially if using Outlook)
  • Stop using Outlook Express, which is vulnerable even in plaintext mode
  • Keeping your host-based security tools (such as AntiVirus) up-to-date
  • Employing web content filtering tools
  • Deploying network-based IPS products
  • Engage in safe browsing/email activities, such as avoiding unknown links

The situation is deemed critical enough that several security threat analysis teams have raised their alert levels on account of this threat, including both and .

If you'd like to get a bit more information about what is being referred to as the ANI vulnerability, then check out the following:

Be advised that although the bulletins discuss Windows 2000 SP4 and later as being affected, it is highly likely that previous version of Windows -- which are currently unsupported by Microsoft -- are also affected.  Users of these older operating systems should consider the use of the unofficial, non-Microsoft patches below:

Please be alert for any updates to these bulletins...

Share Post:
Posted: Monday, April 02, 2007 9:39 AM by Logik!

Comments

Joe Smokie said:

The patch was to be released on April 3rd? I've been to microsoft.com and update.microsoft.com and haven't seen anything about the patch.

# April 3, 2007 2:20 PM
Leave a Comment

(required) 

(required) 

(optional)

(required) 

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

About Logik!

Andrew S. Baker aka ASB aka Logik!

Andrew is an accomplished, hands-on IT Executive with a solid track record of providing timely and cost-effective business solutions using technology. With over 16 years experience in Information Technology, he has proven to be effective both as a Team Leader and as an individual contributor in designing, deploying, securing and maintaining enterprise networks.

His personal interests include Astronomy, Basketball, Bible Study, Chess, Comics, Computers, Family Life Ministries, Reading and Strategy/Role Playing games...

Some of his contributions include several whitepapers on technology and Information Security, the UltraTech Knowledgebase, various postings to technology mailing lists and forums, active participation on LinkedIn Answers, along with a number of interviews for articles published in industry magazines.

View Andrew S. Baker's profile on LinkedIn A condensed version of Andrew's current resume is available here.