Microsoft warns of zero-day XP kernel bug being exploited in the wild

Status
Not open for further replies.

nishaddesilva

Level 3
Thread author
Aug 26, 2012
257
Microsoft has gone public to warn about a zero-day vulnerability in the Windows XP kernel.

Apparently, the bug, dubbed CVE-2013-5065, is being exploited in the wild, though details of exactly how, where, by whom and to what effect are not known.

That makes it rather hard to decide exactly how to respond, but here's what we know so far:

  • The bug is in the NDPROXY.SYS driver, which co-ordinates the operation of Microsoft's Telephony API (TAPI).
  • The exploit doesn't allow remote code execution on its own, only an elevation of privilege (EoP).
  • The vulnerability exists in Windows XP and Server 2003 only.
  • No formal patch or Fixit has been published yet.
  • A simple registry tweak can immunise an XP computer against the vulnerability.
  • The registry tweak has some side-effects you need to know about.

xp-170.png


Source: http://nakedsecurity.sophos.com/201...ay-xp-kernel-bug-being-exploited-in-the-wild/
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
This is a great example of the real world problems Windows XP users will have to face, after EoS. Only expect this list to grow.
 
  • Like
Reactions: sunil22

nishaddesilva

Level 3
Thread author
Aug 26, 2012
257
Earth said:
This is a great example of the real world problems Windows XP users will have to face, after EoS. Only expect this list to grow.

Yes indeed. Hope they move to Windows 7, the next great OS.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top