MS06-040 (updated)

Patch for this one now and troubleshoot the problems later. It’s nasty and in a week or less a million cable/DSL users will be spewing scans all over the Internet.

http://www.microsoft.com/technet/security/Bulletin/MS06-040.mspx

Why am I making such a prediction? Glad you asked:

  1. The Server service is enabled by default
  2. On many servers, you can’t firewall it nor can you disable it without breaking things
  3. There are still plenty of cable and DSL users without firewalls
  4. Even in the enterprise environment, there is a ‘very soft and chewy center’ of the network that is vulnerable to a worm brought in by a laptop fresh off the road.
  5. The speed of POC release has increased tremendously recently, shrinking the window of safe patch deployment.
  6. The list of affected software is significant

My predictions:

  • POC in 48 hours or less (this prediction was correct)
  • Worm in 7 days or less
  • Mainstream media coverage of how “Hackers penetrate and ravage delicate public and privately owned computer systems, infecting them with viruses, and stealing materials for their own ends.”