Originally Posted by jimmm33
I just got an email from MS. Here is part of it:
"As you know, Microsoft released Security Bulletin MS03-039 on September
10, 2003. This bulletin details three critical vulnerabilities in the
Windows operating system and provides instructions for applying the
corresponding patch.
Yesterday, Saturday, September 13th, it came to our attention that a
research company called Immunity published a paper providing guidance on
how to exploit the vulnerabilities patched by Microsoft Security
Bulletin MS03-039. To date we've had no reports of actual exploit code
being publicly available or being used actively in a worm or virus.
If you have applied the patch as advised in Microsoft Security Bulletin
MS03-039, you are protected from exploit code developed using the
guidance provided in this paper. If you have not deployed the patch or
taken additional mitigating actions to protect your environment, you
should be aware that the existence of sample code does make it easier
for an active exploit to be developed. "
The guy on the phone said there was already code out exploiting the vulnerability. Maybe he was refering to "existance of sample code".
It seems they really want to get the message out. I'm guessing that that the warnings will be ignored and that I'll have a very busy few days cleaning up the mess.
I wonder if the virus will get a cool name...