Microsoft is warning consumers using Windows XP Service Pack 1 (SP1) and Windows 2000 SP4 that code has been published that could be used to launch denial-of-service (DoS) attacks. According to the Microsoft security advisory, "the vulnerability could allow an attacker to levy a denial of service attack of limited duration" on Windows XP SP1 if the attacker has valid log-on credentials.
Although the flaw cannot be exploited remotely by an anonymous user, the company said that the affected component is available remotely to users who could gain access through a guest account. The advisory added that users with SP2 are not at risk.
Microsoft has rated the threat as "low" and has not yet developed a patch. In order to launch an attack on Windows 2000 users, the attacker would have to gain remote access to the Remote Procedure Call port. The RPC is generally located behind a firewall and therefore is difficult to access remotely.
|