
It took less than 24 hours for attackers to crank out <A HREF="http://www.pcworld.com/article/id,137166-pg,1/article.html">proof-of-concept code</A> targeting the one critical vulnerability disclosed--and patched--by Microsoft, security researchers warned.
Analysts with Symantec's DeepSight threat network alerted customers that JavaScript exploit code for the critical vulnerability in Windows 2000 that was revealed in Microsoft's monthly patch cycle. The proof-of-concept was posted to the Internet by someone with a Brazilian email address. An hour-and-a-half later, Symantec updated its alert to say that additional exploit code was also available to users of Immunity's popular CANVAS penetration testing software.