How worried should people reasonably be?
How worried should people reasonably be?
There isn't an acknowledged proof-of-concept, so we're not sure that it's exploitable. It hasn't been made clear whether it's wormable, either.
My bet is it will affect XP if it's exploitable, but only for those who added IIS (not default, and not terribly common). It will likely remain unpatched forever, as Microsoft is unlikely to send a patch to an "unsupported" OS again, like they did with the Internet Explorer 0-day [0]
[0]: http://blogs.technet.com/b/msrc/archive/2014/05/01/out-of-ba...
By Microsoft, but I'd bet someone else is definitely going to fix it and distribute a patch. If the amount of effort put forth by the Windows 98SE community in making unofficial patches that let much newer applications work is any indication (look up KernelEx and "98SE unofficial service pack"), XP is going to enjoy an even larger community of unofficial support.
If I recall correctly, SQL Slammer also targeted a server component, but the vulnerable component was also present on some desktop systems, which were then affected.
It wouldn't surprise me if for instance some printer driver listening on a high port also uses the schannel component, and is thus vulnerable.
IBM reported, MS did code review it seems, MS knew about some of these issues for ~6 months.
Patch immediately, people (like me) are running bindiff/etc and a public exploit won't be too far behind.
Not sure how far back it goes yet. All the way? The changes cover code going all the way back to the first SChannel code push, I think. (If XP is exploitable, this may be the XP killing vuln we've all been waiting for.)
It's very serious. Patch immediately.
But that's not a reason to use Firefox on XP. ;)