Friday, April 13, 2007

Microsoft DNS Vulnerability

UPDATE(2007-04-17): This vulnerability is currently being exploited in the wild.

Microsoft released a security bulletin (#935964) last night advising changes to Windows Server 2000 and Windows 2003 Servers running DNS.

It looks like they are recommending a registry hack to block an RPC exploit on DNS servers. Also, the bulletin states that they are working on a full fledged patch, so be looking forward to that.