Wireless worms threaten laptop users

Share this article:

Worms could travel through the airwaves and infect laptops, according to security experts.

Users were warned to update the operating systems following the announcement of vulnerabilities in Intel Centrino's wireless technology. The flaws could theoretically allow hackers to spread malicious code, including worms, wirelessly between laptops.

According to a statement by Intel, the security vulnerabilities exist in the Microsoft Windows drivers for certain versions of their Wireless Network Connection hardware.

"A hacker could exploit these wireless vulnerabilities to run malicious code on an innocent user's laptop, giving them control over other people's PCs or spreading a wireless worm which could leapfrog from one laptop to the next," said Graham Cluley, senior technology consultant for Sophos. "The good news is that we haven't seen any attacks using this exploit yet, but that doesn't mean computer users should be laid back about applying fixes."

"It is essential that all companies remain alert to the latest security issues, and ensure their business computers are properly defended with the latest patches," continued Cluley. "The more time taken to patch a flaw, the greater the opportunity for a malicious hacker to exploit it."

Although Intel has published generic updates to its software, which reportedly fix the issue on its website, the company is recommending that users contact their laptop manufacturers for vendor-specific information and fixes.

Intel has published more information about the security holes, and information on which hardware is affected, on its website here.

Alan Paller, director of research at the SANS Institute, says the vulnerability is significant because it erodes user's trust in their laptop. He added that because the flaw gives attackers privileged rights, they can avoid encryption.

Bugs such as this will continue to be reported in the coming months, Paller predicted.

You can expect wireless drivers to be major targets for the next three to nine months," he said.

Share this article:

Sign up to our newsletters

More in News

Cyber Command tests gov't collaboration in wake of attacks

The two-week exercise, "Cyber Guard 14-1," was completed this month.

Text message spammer settles charges filed by FTC

Text message spammer settles charges filed by FTC

Rishab Verma and his company agreed to settle charges filed by the FTC that Verma sent millions of spam text messages that deceitfully promised free merchandise.

Rhode Island hospital to pay $150K for past data breach

More than 12,000 patients' personal and health information was compromised in a breach at The Women & Infants Hospital of Rhode Island.