
Security experts spotted working source code on underground hacker sites that exploits the most recent vulnerabilities in the Windows RPC DCOM interface, hundreds of machines have already been compromised with Trojan horses bearing the code, and a worm able to infect thousands of systems is not far behind. According to this article in Internet Week, the exploit code found on multiple hacker sites would allow an attacker to obtain authenticated access to RPC DCOM vulnerable computers, which then opens the system to all kinds of mischief, including identify or password theft, deleting files, and initiating a denial-of-service attack.