Sasser was the 2004 malware that exploited a vulnerability in Microsoft’s Local Security Authority Subsystem Service, or LSASS.
The Sasser worm spread across vulnerable Windows 2000 and Windows XP computers by scanning network addresses and sending malicious traffic to the affected service. Unlike many email-based worms, it could propagate without requiring a user to open an attachment.
Infected computers often crashed or restarted repeatedly, disrupting businesses, transport services, and public organizations. Microsoft had issued a security bulletin and patch for the underlying vulnerability before the major outbreak, but many machines remained unprotected.
Sasser was attributed to Sven Jaschan, a German teenager who was arrested in 2004. The case illustrated how quickly an unpatched network service could become a global infection route and helped reinforce the importance of patch management.