SHARE
Facebook X Pinterest WhatsApp

Korgo Worm Targets LSASS Flaw

Written By
thumbnail
Ryan Naraine
Ryan Naraine
May 26, 2004

Anti-virus firms have detected yet another worm exploiting the Local Security Authority Subsystem Service (LSASS) vulnerability that was patched by Microsoft in its April batch of security updates.

The appearance of the W32.Korgo.B worm (also known as Padobot) spreading through the LSASS flaw is a clear indication that PC users have not yet applied the MS04-011 security fix issued by Microsoft on April 13.

According to research firm F-Secure, the network worm is capable of opening TCP ports 113, 3067 and 2041 to receive commands from the virus writers.

“The worm chooses the IP addresses of random machines to infect and attack, similar to other worms which exploit the same LSASS vulnerability,” the company said in an advisory.

The worm attempts to connect to several IRC servers to receive commands and transmit data.

Symantec also issued a separate advisory with a warning that the Korgo worm could open a back door through which an attacker could obtain remote access without authorization.

The appearance of Korgo follows a string of low-impact exploits targeting the LSASS hole. In May, the Sasser worm (W32.Sasser.A) and several variants caused some disruption on corporate networks before Microsoft issued a removal tool to slow the spread of the worm.

The software giant is also working on a plan to include worm removal tools in a new feature called Microsoft Update that’s on schedule for release by this year’s end. With the proliferation of destructive worms like Blaster, NetSky and Sasser escalating daily to pose an ever-greater threat to home users, Microsoft plans to release the new Microsoft Update as part of the larger Windows Update patch management platform.

Depending on the threat level of malicious worms, the software giant will automate the worm removal process. This goes beyond Microsoft’s latest moves to create disinfection tools to deal with major virus outbreaks.

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.