Has anyone heard of a new Microsoft RPC vulnerability today? I’m hearing conflicting reports of a new worm that is exploiting this new vulnerability. We have seen the following process created on our XP workstations:
It apparently creats the following process “NTOSA32.EXE” with a dependancy for RPC. It is also running as the distributed file controller. There also seems to be a link to this file: “NTBKH32.DLL”.
Please forgive siplisity of the post, but that is all the info we are seeing right now. Our AV is looking at it and so far has said little other than it is a new worm. Just trying to see if anyone has seen or heard this.