|
|
|
You are here: News > News > MS placebo patch instantly recalled
| » IT Security NEWS |
| » 25 April 2010 |
| MS placebo patch instantly recalled |
The patch intended for the Media Services, which is incorporated in the Windows 2000 Server, was pulled out by Microsoft even just after it was released. MS10-025 was distributed a week ago and it was removed by the company because the patch was deemed to be useless.
No found exploitation as of the moment
According to Jerry Bryant, a representative of the Security Response Center, the update created by Microsoft was not helpful as a remedy to the problem on the Media Services. The problem, a buffer overflow in the Media Unicast Services, was judged to be a threat that can be abused by attackers even from a distance.
In response to the patch withdrawal, the popular manufacturer of software promises the users that a modified update will be available a week after this one. But then, Microsoft admits that the service is actually not incorporated via default.
Microsoft Corporation reassures the users that the security fault is not yet abused by the online criminals as of today. However, according to the Exploitability Index that was broadcasted eight days prior, the company believes that the web thugs will start abusing the hole not before long.
Immediate remedy is always available for the users
Microsoft suggested an immediate solution, which may be used for the meantime in order to protect the users from any attacks. It is best if one will deactivate the service that possesses vulnerability through the modification of the command line.
It is best to focus on the configuration that makes the service accessible to the Internet. The command line goes as: sc stop nsunicast & sc config nsunicast start= disabled. Additionally, Microsoft specifies that this command line may be used by both parties: the users who have patched up the service using the latest update and those who haven’t touched the patch.
An end for the older products
Based on the most recently published information, Microsoft will still support their older products such as the Windows 2000 Professional and Windows 2000 Server. This is derived from the Extended Support policy, which states that maintenance of the merchandises will reach up to the 13th of July 2010. And, subsequent to the given date, the Microsoft Corporation will no longer distribute free security patches for the two products.
For more information about SecPoint, browse through the given links: SecPoint Press, SecPoint Press, and SecPoint and IT Security News. |