-
Emergency Patches for Windows 200, XP and Server 2003
Microsoft just announced that it’s issuing a special “out of band” Security Bulletin on October 23.
There are basically no details except the fact that MS rates the patches as “Critical” for Windows 2000, XP and 2003. They’re only rated “Important” for Vista and Windows Server 2008.
No idea what’s happening, but the security hole must be easily exploitable. Stay tuned, and for heaven’s sake, don’t install the patch.
UPDATE: The
MS08-067 Security Bulletin is out and the 958644 patch has been made available. If you haven’t yet seen it offered through automatic updates, you will soon.
According to The Register Microsoft was alerted to in-the-wild attacks using this security hole “a couple of weeks ago” but at this point nobody seems to know what or where or when.
Although the New York Times reports that the Immunity team has a working exploit, I haven’t seen any convincing code. My colleague Susan Bradley at Windows Secrets Newsletter recommends that you install the patch immediately. Brian Livingston at Windows Secrets Newsletter published an extra edition just to cover the problem.
I have firewalls working on all of my machines. My antivirus signatures are up-to-date. Those aren’t heroic measures, they’re just common sense. Personally, I’m going to wait a day or maybe two and see what shakes loose.
The sky isn’t falling. Yet.