Microsoft issues Sasser worm patch

Microsoft issues Sasser worm patch

Microsoft customers are being urged to update their patches to protect against a family of internet worms that are spreading fast by exploiting a vulnerability in the Windows operating system.

Link: Viruses wreak havoc on business

Microsoft customers are being urged to update their patches to protect against a family of internet worms that are spreading fast by exploiting a vulnerability in the Windows operating system.

The Sasser worms exploit the Windows ‘Local Security Authority Subsystem Service’ (LSASS) flaw, which Microsoft recently advised on. Four variants of the worm have been reported since 1 May.

Security software firm McAfee warned systems are especially at danger, as the virus does not spread via email and no user action is required to propagate it further, anti-virus companies have warned. It simply instructs vulnerable systems to download and execute its viral code.

‘Computers which are not properly protected with anti-virus updates, firewalls and Microsoft’s security patch are asking for trouble,’ added Graham Cluley, senior technology consultant at anti-virus firm Sophos in a statement. Sophos said it has received many reports of this worm in the wild.

Panda Software’s Luis Corrons also said that Sasser looked a virulent worm. ‘All these signs make for a dark forecast for the beginning of the week when it is expected that the number of incidents will soar at the beginning of the work day,’ he said in a statement.

The worm scans random IP addresses for vulnerable systems. When a vulnerable system is found, the worm sends a specially crafted packet to produce a buffer overrun on LSASS.EXE, which causes the program to crash, and essentially the infected system to crash, requiring Windows to reboot.

‘More infections can lead to increased network traffic and result in severe network slowdowns, like an internal denial-of-service,’ said Joe Hartmann, senior virus researcher and analyst for Trend Micro.

The worm affects Windows 95, 98, ME, NT, 2000 and XP platforms. Customers are recommended to apply the necessary vulnerability patches available from Microsoft to address the LSASS vulnerability.

The Microsoft patch can be found at http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

Share

Subscribe to get your daily business insights

Resources & Whitepapers

The importance of UX in accounts payable: Often overlooked, always essential
AP

The importance of UX in accounts payable: Often overlooked, always essentia...

2m Kloo

The importance of UX in accounts payable: Often ov...

Embracing user-friendly AP systems can turn the tide, streamlining workflows, enhancing compliance, and opening doors to early payment discounts. Read...

View article
The power of customisation in accounting systems
Accounting Software

The power of customisation in accounting systems

2m Kloo

The power of customisation in accounting systems

Organisations can enhance their financial operations' efficiency, accuracy, and responsiveness by adopting platforms that offer them self-service cust...

View article
Turn Accounts Payable into a value-engine
Accounting Firms

Turn Accounts Payable into a value-engine

3y Accountancy Age

Turn Accounts Payable into a value-engine

In a world of instant results and automated workloads, the potential for AP to drive insights and transform results is enormous. But, if you’re still ...

View resource
8 Key metrics to measure to optimise accounts payable efficiency
AP

8 Key metrics to measure to optimise accounts payable efficiency

2m Kloo

8 Key metrics to measure to optimise accounts paya...

Discover how AP dashboards can transform your business by enhancing efficiency and accuracy in tracking key metrics, as revealed by the latest insight...

View article