According to foreign media reports, Microsoft confirmed on Tuesday that hackers have begun to use the Windows XP zero-day vulnerability announced by Google engineers last week to launch attacks.
Has been exploited by hackers
Although Microsoft did not disclose too much detail, other researchers gave relevant information. Graham Cluley, senior technology consultant at Sophos, a network security company, said the hacker had hacked a website and exploited the vulnerability to attack Windows XP users, but he did not disclose information about the site.
Crowley said that Windows XP users can be infected as long as they visit a website with malicious code. This is also one of the two attacks that Microsoft has announced. Another way is to distribute malicious code via email.
Microsoft said that the hacked website has removed malicious code, but more similar attacks may occur in the future. Jerry Bryant, general manager of Microsoft Security Response, said: "Since the full details of this issue have been announced, we expect more attacks in the future."
Google security engineer Tavis Ormandy disclosed the security flaw on Microsoft last Thursday, and he also released a series of "proof-of-concept" attack code. However, Ormandi said that he had reported the vulnerability to Microsoft in the past five days, but the move was still questioned by Microsoft and other researchers.
Google is the first to announce
Crowley said in his blog that Omanti’s behavior is “completely irresponsible”. He said: "I want Microsoft to develop a patch that is not enough for five days. Microsoft needs to thoroughly test it to ensure that it does not cause more problems in order to fix this vulnerability."
Mandy said through Twitter last week that he disclosed the vulnerability because Microsoft did not promise to fix the vulnerability within 60 days. Microsoft confirmed that the company's team had discussed with Ormandi about the release date of the patch.
Microsoft released a security advisory on the vulnerability last Thursday. In addition to acknowledging the existence of this vulnerability, it also provides a temporary solution to help users defend against attacks. The next day, a tool was introduced to automatically unregister the HCP protocol processor. Microsoft said that this will help users block the attack path before the security patch is released.
Crowley said that the attack code currently used by hackers is very similar to the "proof of concept" attack code provided by Omanti. Other security experts believe that this is entirely unexpected.
Microsoft said that although Windows Server 2003 also includes this vulnerability, the system is currently not threatened by related attacks.
According to the regular plan, Microsoft's next patch release will be July 13, but it will still break the rules in an emergency. But Microsoft did not comment on this. Bryant said: "We will continue to monitor the threat situation and will post the latest information through our blog and Twitter."
. It is well known that Word documents in Office office software are commonly used tools. Friends wh
Friends often call to ask: When playing some large games, why the system always pops up x memory can
A lot of friends have come to reinstall the system or upgrade the system, only to find that the long
In the process of using XP system, it is inevitable to leave some browsing records, which is what we
Five tips for recovering Windows XP administrator passwords
Windows XP taskbar fake dead decryption
Why is the text garbled when copying and pasting
Windows Tips: The Administrator account is set with you
XP system installation precautions analysis [map]
Winlogon.exe is corrupted when starting XP
What are the common services for win xp systems? what's the effect?
7 security issues brought by Win XP system default settings
Ten repair methods to eliminate hidden dangers in one step (2)
Win XP new way to build hidden files on the desktop (1)
You must know the use of windows security mode
Hacking offense and defense: the most insidious seven black skills (3)
How does the Win10 system use a virtual optical drive to load an ISO image file?
What is the reason for the failure of win10 official version update KB3081424? How to solve?
How to set display thumbnails in win7 system
System master XP latest application skills six strokes
How to use the netstat command to view DDOS attacks in Linux?
Win10 how to close the app store automatic update
Using email accounts via POP on Win8 and WinRT
Easily customize the built-in variable values of XP system
It turns out that Win 7 can use the heavy name to merge folders