{"id":13497,"date":"2010-07-02T15:19:00","date_gmt":"2010-07-02T13:19:00","guid":{"rendered":""},"modified":"2010-07-02T15:19:00","modified_gmt":"2010-07-02T13:19:00","slug":"beware-windows-xp-attacks","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/software\/13497-beware-windows-xp-attacks.html","title":{"rendered":"Beware Windows XP Attacks"},"content":{"rendered":"<p>A <a href=\"http:\/\/www.microsoft.com\/technet\/security\/advisory\/2219475.mspx\" target=\"_blank\">Microsoft security advisory issued on 10 June<\/a> reported a vulnerability in the Windows Help and Support Center that could allow remote code execution. Real attacks exploiting the vulnerability surfaced on 15 June and as of Wednesday (30 June) the <a href=\"http:\/\/blogs.technet.com\/b\/mmpc\/archive\/2010\/06\/30\/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885.aspx\" target=\"_blank\">Microsoft Malware Protection Center (MMPC) reported<\/a> at least 10 000 distinct computers that have seen the attack.<\/p>\n<p>There is still no fix for the vulnerability available, but Microsoft has provided a workaround that disables the feature creating the vulnerability. An <a href=\"http:\/\/support.microsoft.com\/kb\/2219475\" target=\"_blank\">automated fix<\/a> has been posted on the Microsoft support site.<\/p>\n<p>The MMPC reports that the largest targets of the attack have been the United States, Russia, Portugal, Germany, and Brazil.<\/p>\n<p>According to the security advisory the vulnerability can be exploited by a malicious website, but not automatically through email. A user has to actively visit a malicious site in order to be compromised.<\/p>\n<p>A successful attack can also not gain more rights than the current local user: &ldquo;Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights,&rdquo; said Microsoft.<\/p>\n<p>The versions of Windows affected are:<\/p>\n<p>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Windows XP Service Pack 2 and Windows XP Service Pack 3<\/p>\n<p>2.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Windows XP Professional x64 Edition Service Pack 2<\/p>\n<p>3.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Windows Server 2003 Service Pack 2<\/p>\n<p>4.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Windows Server 2003 x64 Edition Service Pack 2<\/p>\n<p>5.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Windows Server 2003 with SP2 for Itanium-based Systems<\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php?246469-Beware-Windows-XP-vulnerability\"><strong>Windows XP Help and Support Center vulnerability<\/strong><\/a> &lt;&lt; comments and views<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A vulnerability identified on 10 June that remains unpatched has enabled attackers to target 10 000 distinct computers<\/p>\n","protected":false},"author":15,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[],"class_list":["post-13497","post","type-post","status-publish","format-standard","hentry","category-software"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/13497"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=13497"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/13497\/revisions"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=13497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=13497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=13497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}