<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; windows vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/windows-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 03:24:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Security Vulnerability Affects Windows Operating Systems</title>
		<link>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/</link>
		<comments>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 20:18:15 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=16177</guid>
		<description><![CDATA[Microsoft yesterday released a security advisory that described a new security vulnerability affecting several Microsoft operating systems. The article, which was posted only a few hours after the release of security patches for this month&#8217;s patch-day affects the Microsoft Server Message Block (SMB) implementation. The operating systems that are affected by the new vulnerability are [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft yesterday released a security advisory that described a new security vulnerability affecting several Microsoft operating systems. The article, which was posted only a few hours after the release of security patches for this month&#8217;s patch-day affects the Microsoft Server Message Block (SMB) implementation. The operating systems that are affected by the new vulnerability are Windows Vista, Windows Server 2008 and the <a href="http://windows7news.com/">Windows 7</a> Release Candidate.</p>
<p>Operating systems that are not affected include Windows XP, Windows 7 final and Windows Server 2003. No patch is currently available to fix the vulnerability. Microsoft has published workarounds to protect the operating system from possible attacks. </p>
<p><span id="more-16177"></span></p>
<blockquote><p>Disable SMB v2</p>
<p>To modify the registry key, perform the following steps:</p>
<p>Note Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. For information about how to edit the registry, view the &#8220;Changing Keys And Values&#8221; Help topic in Registry Editor (Regedit.exe) or view the &#8220;Add and Delete Information in the Registry&#8221; and &#8220;Edit Registry Data&#8221; Help topics in Regedt32.exe.</p>
<p>1. Click Start, click Run, type Regedit in the Open box, and then click OK.<br />
2. Locate and then click the following registry subkey:<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services<br />
3. Click LanmanServer.<br />
4. Click Parameters.<br />
5. Right-click to add a new DWORD (32 bit) Value.<br />
6. Enter smb2 in the Name data field, and change the Value data field to 0.<br />
7. Exit.<br />
8. Restart the &#8220;Server&#8221; service by performing one of the following:<br />
- Open up the computer management MMC, navigate to Services and Applications, click Services, right-click the Server service name and click Restart. Answer Yes in the pop-up menu.<br />
- From a command prompt and with administrator privileges, type net stop server and then net start server.</p>
<p>Impact of workaround. Host will not be able to communicate using SMB2.</p></blockquote>
<blockquote><p>Block TCP ports 139 and 445 at the firewall</p>
<p>These ports are used to initiate a connection with the affected component. Blocking TCP ports 139 and 445 at the firewall will help protect systems that are behind that firewall from attempts to exploit this vulnerability. Microsoft recommends that you block all unsolicited inbound communication from the Internet to help prevent attacks that may use other ports. For more information about ports, see TCP and UDP Port Assignments.</p>
<p>Impact of Workaround: Several Windows services use the affected ports. Blocking connectivity to the ports may cause various applications or services to not function. Some of the applications or services that could be impacted are listed below:</p>
<p>• Applications that use SMB (CIFS)<br />
• Applications that use mailslots or named pipes (RPC over SMB)<br />
• Server (File and Print Sharing)<br />
• Group Policy<br />
• Net Logon<br />
• Distributed File System (DFS)<br />
• Terminal Server Licensing<br />
• Print Spooler<br />
• Computer Browser<br />
• Remote Procedure Call Locator<br />
• Fax Service<br />
• Indexing Service<br />
• Performance Logs and Alerts<br />
• Systems Management Server<br />
• License Logging Service</p></blockquote>
<p>Users that are running one of the operating systems that are affected by the vulnerability are encouraged to use one of the workarounds to protect their computer systems. More information are available at the Microsoft Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">page</a>.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/operating-system/" title="operating system" rel="tag">operating system</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-vulnerability/" title="windows vulnerability" rel="tag">windows vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/12/04/windows-vista-editions-do-you-know-the-differences/" title="Windows Vista Editions &#8211; Do you know the differences ? (December 4, 2006)">Windows Vista Editions &#8211; Do you know the differences ?</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/06/03/windows-7-to-launch-october-22/" title="Windows 7 To Launch October 22 (June 3, 2009)">Windows 7 To Launch October 22</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/22/windows-7-released/" title="Windows 7 Released (October 22, 2009)">Windows 7 Released</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/06/25/windows-7-price-upgrades-and-preorders/" title="Windows 7 Price, Upgrades And Preorders (June 25, 2009)">Windows 7 Price, Upgrades And Preorders</a> (15)</li>
	<li><a href="http://www.ghacks.net/2008/05/12/windows-7-features-video/" title="Windows 7 Features Video (May 12, 2008)">Windows 7 Features Video</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>January 2009 Microsoft Security Bulletin</title>
		<link>http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/</link>
		<comments>http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 14:49:13 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft security bulletin]]></category>
		<category><![CDATA[microsoft update]]></category>
		<category><![CDATA[security bulletin]]></category>
		<category><![CDATA[update windows]]></category>
		<category><![CDATA[windows patch]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=9886</guid>
		<description><![CDATA[Microsoft has the habit of releasing security patches on one Tuesday each month. Time critical patches can be delivered out of schedule but that did not happen that often in the past. Only one security bulletin has been released on the patch Tuesday in January 2009. Security Bullein MS09-001 has been rated critical for Windows [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has the habit of releasing security patches on one Tuesday each month. Time critical patches can be delivered out of schedule but that did not happen that often in the past. Only one security bulletin has been released on the patch Tuesday in January 2009. Security Bullein <a href="http://www.microsoft.com/technet/security/Bulletin/MS09-001.mspx">MS09-001</a> has been rated critical for Windows XP and Windows Server 2003 respectively moderate for Windows Vista and Windows Server 2008.</p>
<p>The security bulletin resolves three vulnerabilities in Microsoft Server Message Block (SMB) Protocol which could allow remote code execution on affected systems. An attacker could run programs, create new user accounts and view, change or delete data on the computer system. It is <a href="http://blogs.technet.com/msrc/archive/2009/01/13/january-2009-monthly-bulletin-release.aspx">interesting</a> to note that <a href="http://windows7news.com/">Windows 7</a> is affected as well even though it is not mentioned in the security bulletin.</p>
<p>The security vulnerability would be rated as moderate for the upcoming operating system which is why Microsoft will not provide a patch at the current time (They chose to only patch critical security vulnerabilities immediately). A patch will be released with the next public release of Windows 7.</p>
<p><span id="more-9886"></span>Patches can be applied as usual through the various official update channels.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-security-bulletin/" title="microsoft security bulletin" rel="tag">microsoft security bulletin</a>, <a href="http://www.ghacks.net/tag/microsoft-update/" title="microsoft update" rel="tag">microsoft update</a>, <a href="http://www.ghacks.net/tag/security-bulletin/" title="security bulletin" rel="tag">security bulletin</a>, <a href="http://www.ghacks.net/tag/update-windows/" title="update windows" rel="tag">update windows</a>, <a href="http://www.ghacks.net/tag/windows-patch/" title="windows patch" rel="tag">windows patch</a>, <a href="http://www.ghacks.net/tag/windows-vulnerability/" title="windows vulnerability" rel="tag">windows vulnerability</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/05/24/offline-update-6-adds-linux-support/" title="Offline Update 6 Adds Linux Support (May 24, 2009)">Offline Update 6 Adds Linux Support</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/04/13/windows-update-fix/" title="Windows Update Fix (April 13, 2009)">Windows Update Fix</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/" title="Microsoft Patch Day March 2009 (March 10, 2009)">Microsoft Patch Day March 2009</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/05/04/windows-xp-service-pack-3-uxthemedll-patch/" title="Windows XP Service Pack 3 Uxtheme.dll patch (May 4, 2008)">Windows XP Service Pack 3 Uxtheme.dll patch</a> (41)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
