Hackers have given system administrators more reasons to update users' Windows PCs. Over the past two days, they have published two more samples of software that could be used to attack an unpatched Windows system, bringing the tally of new attacks on the OS released into circulation this week to four.
The latest examples, posted to the French Security Incident Response Team (FrSIRT) website on Wednesday and Thursday, take advantage of the same two flaws exploited earlier in the week.
One of these attacks exploits a critical vulnerability in the way that Windows processes files saved in the Windows Metafile graphics format, and it can be used to crash a system. Microsoft fixed this Metafile bug in its MS05-053 security update, released on 8 November, so customers who have not yet applied this patch are the only ones at risk from the new attack.
The second attack targets a flaw in the Microsoft Distributed Transaction Coordinator (MSDTC), which was patched in October's MS05-051 security update. MSDTC is a component of the OS that is commonly used by database software to help manage transactions.
This code appears to be an update to some earlier attack code, which was extremely buggy, according to David Marcus, security research and communications manager at McAfee. "The first exploit [the hacker] did of that code only worked on a bizarre Russian build of Windows 2000," he said. "The second revision seems to be a bit more stable."
"We definitely see that one as a problem, and that's causing a lot of chatter," Marcus said. "The underground is latching on to this thing and they're figuring out some way to turn this into a worm candidate."
Most security experts expect Microsoft to patch this IE flaw by the time it releases its next security update on 13 December. To make things easier for systems administrators, Microsoft normally releases patches on the second Tuesday of every month, but Marcus believes that the publicity surrounding the matter may prompt Microsoft to act sooner.
"I think for its own good public relations, it'll eventually release a patch out of cycle," he said. "It's getting too much publicity."