Which 2004 malware exploited a vulnerability in Microsoft’s LSASS service?

The story behind the answer

Sasser was the 2004 malware that exploited a vulnerability in Microsoft’s Local Security Authority Subsystem Service, or LSASS.

The Sasser worm spread across vulnerable Windows 2000 and Windows XP computers by scanning network addresses and sending malicious traffic to the affected service. Unlike many email-based worms, it could propagate without requiring a user to open an attachment.

Infected computers often crashed or restarted repeatedly, disrupting businesses, transport services, and public organizations. Microsoft had issued a security bulletin and patch for the underlying vulnerability before the major outbreak, but many machines remained unprotected.

Sasser was attributed to Sven Jaschan, a German teenager who was arrested in 2004. The case illustrated how quickly an unpatched network service could become a global infection route and helped reinforce the importance of patch management.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: