SHARE
Facebook X Pinterest WhatsApp

‘Detailed Exploit’ Published for Critical Windows Flaw

Written By
thumbnail
Ryan Naraine
Ryan Naraine
Jun 26, 2006

In an unusual move, Microsoft has released a formal security advisory to warn of the publication of “detailed exploit code” that targets a critical Windows vulnerability.

The software maker’s security response unit is strongly urging Windows users—especially businesses running Windows 2000—to patch the vulnerabilities addressed in the MS06-025 bulletin because of the potential for a worm attack.

The MS06-025 bulletin provides fixes for a pair of code execution flaws in the RRAS (Routing and Remote Access Service) in Windows. On Windows 2000 systems, the flaws carry a “critical” rating because it presents a remote unauthenticated attack vector.

Both flaws could allow a remote attacker to take “complete control” of an affected system and because a blow-by-blow exploit has been published on the Web, Microsoft is bracing for the possibility of a disruptive attack similar to the Zotob worm that hit several high-provide targets in August 2005.

The exploit code was released by security consultant HD Moore as part of the Metasploit Framework, an open-source tool for penetration testing and exploit development.

“When something like this happens so quickly after release we wanted to highlight that fact, and let you know that we’re not currently aware of any active attacks utilizing this exploit code at this time,” said Microsoft security program manager Stephen Toulouse.

“We have confirmed that the exploit code does not affect users who have installed the update detailed in MS06-025 on their computers. So we continue to recommend that customers apply the that update,” Toulouse added.

As is customary, Microsoft’s advisory included a knock against “certain security researchers” for breaching what it described as “commonly accepted industry practice” with the publication of published exploit code that puts computer users at risk.

Read the full story on eWEEK.com: ‘Detailed Exploit’ Published for Critical Windows Flaw

Recommended for you...

What do Amazon, Microsoft, Meta, and IBM Have in Common? Tape Storage
Drew Robb
Aug 15, 2022
What Does Quantum Computing Mean for IT?
Devin Partida
Aug 11, 2022
Solving the Video Surveillance Retention Challenge 
Drew Robb
Jul 28, 2022
Top 6 IT Challenges in Healthcare
Lauren Hansen
Jun 21, 2022
CIO Insight Logo

CIO Insight offers thought leadership and best practices in the IT security and management industry while providing expert recommendations on software solutions for IT leaders. It is the trusted resource for security professionals who need to maintain regulatory compliance for their teams and organizations. CIO Insight is an ideal website for IT decision makers, systems integrators and administrators, and IT managers to stay informed about emerging technologies, software developments and trends in the IT security and management industry.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.