Thursday, October 23, 2008

Microsoft mystery patch revealed soon

note:updated info here

Today Microsoft has all system administrators and security professionals on alert. This because of a patch that will be released today. Actually in a couple of hours more details will be revealed. The patch is special because it's being released outside of the normal patch Tuesday schedule.

The info will be posted on below link later today.

http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx

Because nearly all Windows version are affected and it's a remote code execution threat one must think that is concerns a service running on normal ports like http, smtp or maybe an ASP.NET threat. But also possible is something with the TCPIP threat which was disclosed a couple of weeks ago. This in combination with proof that it could create a memory leak in a Windows system might be combined with a buffer overflow and code execution.

So everybody in the security business ad dealing with Microsoft Windows products should be on alert. Probably within a few hours after details are released the reverse engineering starts and exploits will likely be released in the wild.

I will add a new post when more information is available. (new post added here)

Let me know what you think.

No comments: