Monday, November 16, 2009

Microsoft confirms first zero-day Windows 7 exploit


Not a month after Windows 7's official launch comes news of the very first zero-day exploit, and it has been confirmed by Microsoft itself. The vulnerability, first reported by Canadian researcher Laurent Gaffie last Wednesday, exists in not just Windows 7 but also Server 2008 R2 systems. This said vulnerability could "cause a system to stop functioning or become unreliable," according to a Microsoft-issued advisory. Microsoft says that it may patch the problem, though so far it is generally downplaying the issue, suggesting that users instead work on it themselves by blocking TCP ports 139 and 445 at the firewall.

Source: [Computerworld]