microsoft

Attacks begin against critical Patch Tuesday bug

Steven Parker   on 11 April 2008 - 10:40 · 21 comments & 13705 views

Advertisement (Why?)
Only Windows XP SP3 -- that's right, SP3 -- is safe. Hackers are trying to exploit a critical Windows vulnerability just patched on Tuesday, security researchers said this afternoon -- and the only version of Windows not at risk is the unfinished Windows XP Service Pack 3 (SP3). Fortunately, attackers' incompetence means that these initial sorties have been unsuccessful, Symantec Corp. said in a brief warning to customers of its DeepSight threat service. "The DeepSight honeynet has observed in-the-wild exploit attempts targeting a GDI vulnerability patched by Microsoft on April 8, 2008," said Symantec in its alert.

On Tuesday, Microsoft Corp. patched two bugs, both pegged as "critical," in Windows' GDI, or graphics device interface, one of the core components of the operating system. According to Microsoft, every current version of Windows, including the very newest, Vista SP1 and Server 2008, is open to attack. The vulnerabilities can be triggered by malformed WMF (Windows Metafile) or EMF (Enhanced Metafile) image files, Microsoft noted in its accompanying advisory.

News Source: Computer World

Post a comment · Send to friend Comments · There are 21 additional comments
(3 replies) #1 HawkMan on 11 Apr 2008 - 11:39
Only Windows XP SP3 -- that's right, SP3 -- is safe. Hackers are trying to exploit a critical Windows vulnerability just patched on Tuesday


if it was patched on tuesday, wouldn't all windows versions then be safe, provided you have patched yoru system. while SP3 isn't even released yet, so it can't really take the title of only safe windows release, specially if actual released versions have been patched.
#1.1 Enigma776 on 11 Apr 2008 - 12:16
I don't think you read it right, It's saying that the patch which was suppose to fix it has a security flaw of it's very own. So another patch is required to stop the attacks. SP3 is currently the only thing that can prevent the attack as of now.
#1.2 jasondefaoite on 11 Apr 2008 - 12:37
(Enigma776 said @ #1.1)
I don't think you read it right, It's saying that the patch which was suppose to fix it has a security flaw of it's very own. So another patch is required to stop the attacks. SP3 is currently the only thing that can prevent the attack as of now.


Actually I think he's right. When the patches were released on Tuesday, hackers took note of what was being fixed, and began attacking that specific vulnerability on systems without the patch applied.
#1.3 Draganta2000 on 11 Apr 2008 - 18:34
(Enigma776 said @ #1.1)
I don't think you read it right, It's saying that the patch which was suppose to fix it has a security flaw of it's very own. So another patch is required to stop the attacks. SP3 is currently the only thing that can prevent the attack as of now.


I don't think you are reading it at all. "Microsoft's GDI patches can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services." -Taken from Computer World Article
(9 replies) #2 n_K on 11 Apr 2008 - 12:46
err, so can someone tell me if XP SP1 is protected ?
#2.1 _dandy_ on 11 Apr 2008 - 13:56
(n_K said @ #1)
err, so can someone tell me if XP SP1 is protected ?


If you're still on SP1, you have much more of an attack surface than this one particular bug.
#2.2 XerXis on 11 Apr 2008 - 16:15
offcourse not, xp sp1 isn't supported anymore (for a good reason)
#2.3 Draganta2000 on 11 Apr 2008 - 18:36
(n_K said @ #2)
err, so can someone tell me if XP SP1 is protected ?


Very Funny
#2.4 n_K on 11 Apr 2008 - 19:20
(Draganta2000 said @ #2.3)
(n_K said @ #2)
err, so can someone tell me if XP SP1 is protected ?


Very Funny

?

All I want to know is if SP1 is vun. to this attack or not ?
#2.5 Tantawi on 12 Apr 2008 - 03:31
(n_K said @ #2.4)
All I want to know is if SP1 is vun. to this attack or not ?


Please do yourself a favor, and install SP3 as soon as it's released on Windows update this month.
#2.6 +warwagon on 12 Apr 2008 - 06:16
Yes Sp1 is vulnerable. But not just to this exploite but to MANY more. Either install Sp2 and ALL the updates as of current or unplug your computer from the Internet

Thank You.
#2.7 strekship on 12 Apr 2008 - 07:17
SP1 users have more to worry about than this one exploit.
#2.8 n_K on 12 Apr 2008 - 11:12
(Tantawi said @ #2.5)
(n_K said @ #2.4)
All I want to know is if SP1 is vun. to this attack or not ?


Please do yourself a favor, and install SP3 as soon as it's released on Windows update this month.

Humm will do when I free up more than 40MB of space
#2.9 Esvandiary on 12 Apr 2008 - 11:50
(n_K said @ #2.
Humm will do when I free up more than 40MB of space

I'm sure all the extra malware XP SP1 is susceptible to will help you increase a lot more than 40MB of space.
(1 reply) #3 xpclient on 11 Apr 2008 - 16:28
If they're already patched I don't get what all this is about. Some one slap the author of this article for me.
#3.1 BigCheese on 11 Apr 2008 - 20:28
I think the vulnerabilities were patched on tuesday, but some people are trying to attack computers that haven't yet had the patches applied. But, I agree, the article is really confusing.
#4 soldier1st on 11 Apr 2008 - 17:11
ppl who are still on sp1 should just update to sp2 and be done with it and if your not gonna update then you should either prep urself or get nailed by that bug(you should stay current)
#5 Chrono951 on 11 Apr 2008 - 18:06
I guess this would only affect those people who don't install or have windows automatically install updates.
#6 avidracer on 11 Apr 2008 - 18:33
please give me SP3 RTM........
#7 toadeater on 11 Apr 2008 - 23:14
I don't believe Symantec.
#8 +ispamforfood on 12 Apr 2008 - 06:00
Well, considering how much practice MS has had, i sure hope theyre the fastest! Still like 'em tho.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)