Plug&Play worm Zotob prowling the Internet A new worm called Zotob is making use of the loophole in Windows' plug-and-play interface to emerge last week to infect Windows systems via the Net. Especially vulnerable are users of Windows 2000 who have as yet failed to incorporate the appropriate patch.
Anzeige
A new worm that goes by the name of Zotob is making use of the loophole in Windows' plug-and-play interface to emerge last week to infect Windows systems via the Net. Microsoft made a patch for this problem available last week; only a few days later, however, the first exploits were published. Especially vulnerable are unpatched Windows 2000 systems, because they allow anonymous access via the Internet to the plug-and-play services.
For Windows XP systems with Service Pack 2 and for Windows 2003 Server to access the same services a successful authentication as administrator is, according to Microsoft, required. In the case of Windows XP with Service Pack 1 access to a limited user account is all it takes. Nonetheless, Zotob cannot infect these without, for example, simultaneously making the odd successful guess at access data. The full story may be accessed at http://www.heise.de/english/newsticker/news/62815.
Posted by zmercer at 08:45 AM |