Microsoft Windows Server RPC bug finds new way to spread

Share this article:
Exploits taking advantage of a Windows Server Service vulnerability still are running rampant, nearly 1-1/2 months after Microsoft delivered an emergency fix, researchers said Friday.

Symantec, over the holidays, spotted another round of infections in the form of a worm known as W32.Downadup. Microsoft is terming the malware Win32/Conficker.

The latest variant finds a new way to take advantage of the highly critical bug, which involves the Remote Procedure Call (RPC) protocol, Symantec researchers said on Friday. In prior attacks, an attacker could execute remote code by sending a specially crafted RPC request.

However, the new exploit "can also spread through corporate networks by infecting USB sticks and accessing weak passwords," Symantec's Security Response department said Friday in a forum post.

"W32.Downadup.B creates an autorun.inf file on all mapped drives so that the threat automatically executes when the drive is accessed," according to Symantec. "The threat then monitors for drives that are connected to the compromised computer in order to create an autorun.inf file as soon as the drive becomes accessible."

On Oct. 23, Microsoft delivered a rare, out-of-cycle patch for the flaw, which was being actively exploited in targeted attacks.

Matt McCormack of the company's Malware Protection Center wrote on Dec. 31 that researchers have detected a new outbreak of the attack, mostly on machines that have yet to apply the patch.
Share this article:

Sign up to our newsletters

More in News

Brazilian president signs internet 'Bill of Rights' into law

Brazilian president signs internet 'Bill of Rights' into ...

President Dilma Rousseff signed the legislation on Wednesday at the NetMundial conference in Sao Paulo.

Android trojan sends premium SMS messages, targets U.S. users for first time

Android trojan sends premium SMS messages, targets U.S. ...

An SMS trojan for Android, known as FakeInst, has been observed sending premium SMS messages to users all over the world, including, for the first time, the United States.

Report: DDoS up in Q4 2013, vulnerability scanners leveraged to exploit sites

Report: DDoS up in Q4 2013, vulnerability scanners ...

Researchers observed 346 DDoS attacks in the final quarter of 2013 and attackers used Vega and Skipfish vulnerability scanners to exploit web flaws at financial companies.