An exploit code has popped up on several hacking Web sites for a critical Microsoft flaw only days after Redmond issued a patch for it.
The patch, which addresses a vulnerability in the Windows Plug-and-Play system, automatically recognizes and configures devices plugged in to the computer.
The exploit can lead to a remote system compromise, allowing an attacker to take control of an affected computer, according security firm eEye.
This flaw is similar to other serious vulnerabilities that have been used in the past to create worms such as Blaster and Sasser, eEye said.
read more