Webtrends Tracking Code
 
UK Home >  OUT-LAW News >  News Archive >  2003 >  September 2003 >  Windows flaws du jour; patches served

Windows flaws du jour; patches served

OUT-LAW News, 12/09/2003

Three flaws in Windows operating systems were revealed by Microsoft on Wednesday. Identified as 'critical', Microsoft says these latest vulnerabilities could be exploited in the same way as the flaw hit by the recent MSBlaster worm.

Users are urged to take precautions and make sure they patch the flaws now.

According to the Microsoft Security Bulletin, two of the flaws are what are called buffer overruns, and would allow an attacker to download material onto an infected computer. The third flaw relates to what is known as the remote procedure call, and could be used to allow the attacker complete access to the computer.

Taken together the flaws, carrying Microsoft's maximum alert, allow the hacker to launch a denial of service attack – where a server is so overloaded with requests that it crashes. It's all very similar to the chaos caused by the recent MSBlaster worm.

The MSBlaster worm spread rapidly around the globe and infected over 500,000 computers by the time it tried to launch its denial of service attack on a Microsoft site. It had the unfortunate side effect of causing infected computers to crash and reboot every few minutes.

The new flaws affect the following:

  • Microsoft Windows NT Workstation 4.0;
  • Microsoft Windows NT Server® 4.0;
  • Microsoft Windows NT Server 4.0, Terminal Server Edition;
  • Microsoft Windows 2000;
  • Microsoft Windows XP;
  • Microsoft Windows Server 2003.

Security company Symantec has warned that it believes "that active exploitation and creation of internet worms targeting this vulnerability is imminent." Users are urged to download the relevant Microsoft patch immediately.

See:

See also:

 

OUT-LAW Recommends

Free OUT-LAW seminars
- Making your contract work
- Information security
Six cities, October & November

This week's podcast
Are ISPs about to betray our trust?

Winner at 2008 Webby Awards

OUT-LAW star: link to the home page
Disclaimer: This was printed from OUT-LAW.COM, a service of international law firm Pinsent Masons. We hope you find this content useful. However, please note that nothing in this document constitutes specific legal advice. You should consult a suitably qualified lawyer on any specific legal problem or matter. Any questions, please email info@out-law.com.