Article 54D1K Exploit code for wormable flaw on unpatched Windows devices published online

Exploit code for wormable flaw on unpatched Windows devices published online

by
Dan Goodin
from Ars Technica - All content on (#54D1K)
windows-10-s-wallpaper-800x450.jpg

Enlarge (credit: Windows)

A researcher has published exploit code for a Microsoft Windows vulnerability that, when left unpatched, has the potential to spread from computer to computer with no user interaction.

So-called wormable security flaws are among the most severe, because the exploit of one vulnerable computer can start a chain reaction that rapidly spreads to hundreds of thousands, millions, or tens of millions of other vulnerable machines. The WannaCry and NotPetya exploits of 2017, which caused worldwide losses in the billions and tens of billions of dollars respectively, owe their success to CVE-2017-0144, the tracking number for an earlier wormable Windows vulnerability.

Also key to the destruction was reliable code developed by and later stolen from the National Security Agency and finally published online. Microsoft patched the flaw in March 2017, two months before the first exploit took hold.

Read 12 remaining paragraphs | Comments

index?i=4Y0f5d-7fL0:MdZF0RQSNNM:V_sGLiPB index?i=4Y0f5d-7fL0:MdZF0RQSNNM:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments