The code takes advantage of a bug related to plug-and-play technology in Windows 2000 and Windows XP. Microsoft provided a patch for the flaw on Oct. 11 in security bulletin MS05-047, along with . The software maker rated the issue "important."
The plug-and-play exploit code is not the first to surface for a flaw that was fixed in Microsoft's October patch cycle. Other exploits have been published on the Internet or reported privately. Release of such code typically is a prelude to an attack. However, while, attacks have yet to appear.
The exploit causes a vulnerable system to crash, but it's unlikely to be used for a worm, a Symantec representative said. "It does not gain local access to machines," the representative said.
A Microsoft representative said Friday that the company is aware of the latest exploit code, but noted that no attacks were reported. "Microsoft is actively monitoring this situation to keep customers informed," the representative said in an e-mailed statement.
The vulnerability lies in the same Windows component that Microsoft provided a patch for two months ago. That flaw led to, which took down systems across the U.S., including at cable news station CNN, television network ABC and The New York Times.
Microsoft urges users to apply the MS05-047 patch. Users who updated their system with theare somewhat protected against this flaw as well, the company said. However, if that patch is not installed, the latest flaw could be exploited remotely by an anonymous user on Windows 2000 systems, the company said.