New vulnerabilities in Windows can remotely hijack user PC

  

According to foreign media reports, a security researcher recently revealed a new Windows unrepaired vulnerability. Some experts believe that this vulnerability may lead to an attacker remotely hijacking a victim's PC.

Microsoft said the company is investigating the vulnerability, but Microsoft did not provide any analysis of the vulnerability.

Jerry Bryant, group manager for the Microsoft Security Response Center (MSRC), said that Microsoft is investigating a publicly announced vulnerability in the Windows SMB (Server Information Module). Once the investigation is completed, the company will take appropriate measures to protect it. consumer. These measures may include a patch in the monthly security update, a patch outside the release cycle, or additional guidance to help consumers protect themselves.

On Monday, a researcher named "Cupidon-3005" published the attack code for this Windows vulnerability. The vulnerability is located in the "mrxsmb.sys" driver's "BowserWriteErrorLogEntry()" function. in. It is reported that this driver is mainly to process the request of the server message block protocol sent to Windows for network communication, and Windows SMB (Server Information Module) is mainly used to provide file and printer sharing to Windows computers.

According to news from French security company Vupen, the security level of this Windows SMB (Server Information Module) vulnerability is the highest "critical" level, and once it is successfully exploited by an attacker, it will lead to a denial of service attack. Or completely control the vulnerable computer, the former will cause the Windows system to crash and produce a "blue screen of death" phenomenon.

The Danish vulnerability tracking company Secunia rated the security level of this Windows SMB vulnerability as "medium critical" and said the attacker could exploit the vulnerability to attack the victim PC.

Secunia pointed out that once an attacker successfully exploits this vulnerability, it will be able to cause arbitrary code execution.

Vupen confirmed that vulnerabilities in Windows XP SP3 and Windows Server 2003 SP2 will be under attack, while Secunia said other versions of Windows may also be affected.

Copyright © Windows knowledge All Rights Reserved