Microsoft closes a critical network flaw

166
vote

Microsoft kicked off the new year by fixing three vulnerabilities on its first regularly scheduled patch day.

The most serious flaw affects the way that Windows systems handle storing the data associated with Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) network requests. The vulnerability affects both Windows Vista and Windows XP Service Pack 2 and is rated Critical by Microsoft for those operating systems. An attacker could take control of a user's machine by sending it a specially-crafted IGMP or MLD request, Microsoft stated in its bulletin.

"An attacker who successfully exploited this vulnerability could take complete control of an affected system, ... (and) could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft stated.
Continue reading here....