March 17, 2003 12:09 PM PST

Security hole in Windows 2000 servers

Microsoft warned customers on Monday that a security hole in Windows 2000 and the company's Web server software is allowing online attackers to take control of corporate servers.

Because the vulnerability is being actively exploited by Internet vandals, Microsoft advised customers to apply a patch or use a workaround to defend against the attack as soon as possible.

"We have had isolated reports from customers that (the flaw) is getting exploited," said Iain Mulholland, security program manager for Microsoft's security response center. "We have issued a number of workaround options. Ultimately, the only way to protect yourself is apply a patch, but we respect companies' need to test first."

The incident nearly embodies a worst-case scenario for how a vulnerability should be discovered. Companies generally hope that researchers will discover a flaw, inform the software maker, and then wait to announce the flaw until a patch is prepared. When online vandals have access to a "zero day" vulnerability--a flaw that companies aren't warned of--they can break into far more computers before software makers understand what is going on.

In this case, Microsoft learned of the vulnerability after online hackers used the flaw to breach the security of a customer's Web servers last Wednesday, Mulholland said. He said the incident is being investigated by federal law enforcement.

Atlanta-based Internet Security Systems also had a customer affected and confirmed that a tool to take advantage of the flaw is being distributed on the Internet.

Still, attacks are not yet widespread, said Dan Ingevaldson, team leader for Internet Security Systems' research and development group. "We have sensors that are deployed all over the world, and we have not seen them light up with this attack," he said. "So we believe the incidents are contained at this point, but we don't expect that to last very long."

The flaw, known as a buffer overflow, is in a component of the software that handles the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol in Microsoft's Internet Information Server (IIS). A specially formatted Web request to the WebDAV component can overflow the memory allocated to such requests and cause another, malicious program to be run instead. The technique can be used to take control of the server.

The flaw affects only IIS 5.0 on Windows 2000 servers. IIS 4.0 on Windows NT and IIS 5.1 on Windows XP are not affected.

How quickly the patch and workarounds get applied is a big question for the software giant. In the past, system administrators have been slow to apply the software fixes. Patches released six months before the Slammer worm didn't prevent that malicious program from spreading to nearly 200,000 Microsoft SQL servers.

This time around, the company doesn't have a head start on those abusing the flaw. Whether that threat spurs companies to apply the patches more quickly remains to be seen.

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    At 10 years old, whither Google?

    Daniel Sieberg of CBS News looks at how the company grew exponentially from start-up to superstar and part of our culture, but what's ahead?

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    At the TechCrunch50, an unfair advantage?

    Inside baseball: How Webware and other blogs can compete with TechCrunch in covering the TechCrunch50 event.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.