Business Services Industry
Internet Security Systems Discovers Critical Vulnerability In Microsoft Windows Plug And Play Service, Preemptively Protects Customers; Company Also Protects from Additional Microsoft Vulnerabilities
Business Wire, August 9, 2005
ATLANTA -- Internet Security Systems, Inc. (ISS) (NASDAQ: ISSX) today announced that the company's X-Force(R) Research and Development Team has discovered a critical vulnerability in the Windows Plug and Play service, and has delivered preemptive customer protection for this and other vulnerabilities announced today in Microsoft's monthly security bulletin.
Plug and Play is a Windows service designed to handle installation, configuration and notification of new devices. The flaw in Plug and Play discovered by X-Force is remotely exploitable in the default configuration of Windows 2000 and is present in all modern Windows operating systems. Currently, no exploits for this flaw are available to the public at large; however, ISS X-Force believes there is a probability that this vulnerability will be exploited as a worm, most likely in a targeted fashion, but also possibly as a broader worm attack against the Windows 2000 Operating System.
Successful exploitation of this vulnerability could be leveraged to gain complete control of target systems and might lead to malware installation, exposure of confidential information or further network compromise. Due to the widespread use of the affected operating systems and the critical nature of the component affected, it is likely that servers and desktops used for a wide variety of purposes are vulnerable to compromise.
ISS customers have been preemptively protected from this issue since March of this year.
Additional Vulnerabilities - ISS is also tracking and providing customers with preemptive protection for issues in two other Microsoft technologies prevalent in the Windows operating system. The first technology, the Windows Print Spooler service, is essential for both local and network printing and contains a remotely exploitable heap-based buffer overflow that could allow an attacker to fully compromise an affected machine without any user interaction. X-Force is also looking into issues in JPEG image parsing in Internet Explorer. These issues could also be used to remotely compromise a system with minimal user interaction if a user could be induced to view a malicious image.
Available Protection - Organizations that have deployed ISS products from the Proventia(R) Enterprise Security Platform or that use ISS Managed Security Services are preemptively protected against these threats. For additional information on affected infrastructure or on Microsoft's suggested methods of mitigating exposure, please visit: http://www.microsoft.com/technet/security/current.aspx.
> For more information on Internet Security Systems(TM) preemptive protection offerings, please visit: http://www.iss.net/proof/preemptiveprotection/.> The full ISS X-Force advisory on Windows Plug and Play can be found at: http://xforce.iss.net/xforce/alerts/id/202.> The full ISS X-Force alert on today's Microsoft updates can be found at: http://xforce.iss.net/xforce/alerts/id/203.> About Internet Security Systems, Inc.Internet Security Systems, Inc. (ISS) is the trusted expert to global enterprises and world governments, providing products and services that protect against Internet threats. An established world leader in security since 1994, ISS delivers proven cost efficiencies and reduces regulatory and business risk across the enterprise. ISS products and services are based on the proactive security intelligence conducted by ISS' X-Force(R) research and development team - the unequivocal world authority in vulnerability and threat research. Headquartered in Atlanta, Internet Security Systems has additional operations throughout the Americas, Asia, Australia, Europe and the Middle East. For more information, visit the Internet Security Systems Web site at www.iss.net or call 800-776-2362.
Internet Security Systems is a trademark and X-Force and Proventia are registered trademarks of Internet Security Systems, Inc. All other companies and products mentioned are trademarks and property of their respective owners.
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- CUSTOMER WIN: BEA China Selects BMC Software to Deliver Business Service Management Platform
- SiBEAM Invigorates CE and PC Industries with Launch of Products and Partnerships to Fuel WirelessHD® Expansion
- Research and Markets: China Chocolate Market Overview 2009-2010: a Guide to Selling Chocolate in China with Full Forecasts to 2010 and Key Statistical Data
- Project Management Institute Global Accreditation Center for Project Management Education Programs Extends Agreement with China National Steering Committee of Professional Education of Masters of Engineering
- Research and Markets: China Sulfur Industry Report Reveals the Market Increased Greatly, Importing 9.72 Million Tons in the First Nine Months Alone in 2009
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- Using object-oriented analysis and design over traditional structured analysis and design
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- LIFO vs. FIFO: a return to the basics
- Design a commission plan that drives sales - Sales Commissions



