News

Gartner: Port Sniffing Spike May Signal Effort to Exploit Microsoft SMB Flaw

An analyst with Gartner warned customers that a recent spike in scanning activity on TCP Port 445 may mean attackers are gearing up to exploit a flaw patched last week by Microsoft in the widely used SMB protocol.

Gartner analyst John Pescatore issued the warning this week about an apparent increase in sniffing on Port 445 that occurred last Friday. "The apparent increase in 'sniffing' on Port 445 is a serious concern for enterprise security managers, because it may indicate an impending mass malicious-code attack," Pescatore wrote.

The port is used by the Microsoft Server Message Block (SMB) protocol. Microsoft posted a patch for a critical flaw in SMB on June 14. The patch was contained in security bulletin MS05-027. An attacker could potentially use the flaw to take control of computers over the Internet.

A Microsoft spokesperson said the Microsoft Security Response Center is aware of the spike in sniffing activity.

"As part of the Microsoft Security Response Center process, once they release those patches, they continue to actively monitor the environment. They're always monitoring for any malicious activity. They're not seeing anything that raises any alarm," the spokesperson said.

Among reasons Microsoft isn't overly concerned yet about the spike are that because port scans are non-specific they could indicate searches for a number of other vulnerabilities, many on other platforms; that no exploit code is publicly circulating; and that no customers have reported being attacked.

Pescatore's research note advised customers to accelerate efforts to ensure that all Windows systems get patched, to implement workarounds until patching is complete, and to review firewall settings to make sure Port 445 access is blocked wherever possible.

The Microsoft spokesperson issued similar advice as standard precautions.

Click here to view Microsoft Security bulletin MS05-027.

See also A Look at the Microsoft Security Response Center's Playbook.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.