CGISecurity Logo

MS09-048: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution

Microsoft has just published a remote vulnerability in the windows TCP/IP stack.

"This security update resolves several privately reported
vulnerabilities in Transmission Control Protocol/Internet Protocol
(TCP/IP) processing. The vulnerabilities could allow remote code
execution if an attacker sent specially crafted TCP/IP packets over the
network to a computer with a listening service. Firewall best practices
and standard default firewall configurations can help protect networks
from attacks that originate outside the enterprise perimeter. Best
practices recommend that systems that are connected to the Internet
have a minimal number of ports exposed."

Patch: http://update.microsoft.com/microsoftupdate
More info: http://www.microsoft.com/technet/security/Bulletin/MS09-048.mspx