1. Home
  2. Computing & Technology
  3. Internet / Network Security

Sasser Worm Spreading
Exploits LSASS Vulnerability From MS04-011 Security Bulletin

From , former About.com Guide

On April 13 Microsoft released their security bulletins for the month of April. The first one, MS04-011, was a security roll-up package which identified a number of new vulnerabilities and included the fixes for these new vulnerabilities as well as many old vulnerabilities.

By exploiting a buffer overflow vulnerability in LSASS.exe (Local Security Authority Server Service), a Windows process which handles local security functions, this worm is able to spread from vulnerable machine to vulnerable machine without requiring any user interaction or intervention.

According to antivirus firm Network Associates, a side effect of being infected is that LSASS.exe will crash resulting in a forced system reboot on most systems.

Infected machines will attempt to scan different IP address ranges searching for other vulnerable systems to infect and will open TCP ports 5554 and 9996.

Antivirus vendors are ranking this as a Medium threat already which means that it is spreading rapidly. Make sure you have your antivirus software updated and, more importantly, make sure you apply the patch for MS04-011 to your system before a new worm comes out exploiting a different vulnerability from this security bulletin.

Explore Internet / Network Security
About.com Special Features

The Best Web Trends of the Decade

A look back at the best innovations, ideas and technologies over the last 10 years, More >

Family Tech Center

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

  1. Home
  2. Computing & Technology
  3. Internet / Network Security
  4. Basic Security
  5. Secure Your Windows PC
  6. Securing Windows XP / 2003
  7. Sasser Worm Exploits MS04-011 Vulnerability

©2009 About.com, a part of The New York Times Company.

All rights reserved.