Еще одна дырочка...снова бежим, все туда же | Предыдущая тема : Следующая тема  | | | Сообщение |
Добавлено: 11 апр. 2003 08:47 Заголовок сообщения: И еще две дырки, бежим на WindowsUpdate | | - ---
Title: Flaw In Winsock Proxy Service And ISA Firewall Service
Can Cause Denial Of Service (331066)
Date: 09 April 2003
Software: Microsoft Proxy Server 2.0, Microsoft ISA Server
Impact: denial of service
Max Risk: Important
Bulletin: MS03-012
Microsoft encourages customers to review the Security Bulletins
at:
http://www.microsoft.com/.../MS03-012.asp
http://www.microsoft.com/.../ms03-012.asp
- ---
- ---
Title: Flaw in Microsoft VM Could Enable System Compromise
(816093)
Date: 09 April 2003
Software: Microsoft VM
Impact: Allow attacker to execute code of his or her choice
Max Risk: Critical
Bulletin: MS03-011
Microsoft encourages customers to review the Security Bulletins
at:
http://www.microsoft.com/.../MS03-011.asp
http://www.microsoft.com/.../ms03-011.asp
- --- |
Добавлено: 17 апр. 2003 07:57 Заголовок сообщения: Еще одна дырочка...снова бежим, все туда же | | - ---
Title: Buffer Overrun in Windows Kernel Message Handling could
Lead to Elevated Privileges (811493)
Date: 16 April 2003
Software: Microsoft Windows NT 4.0, Windows 2000, and Windows XP
Impact: Local Elevation of Privilege
Max Risk: Important
Bulletin: MS03-013
Microsoft encourages customers to review the Security Bulletins at:
http://www.microsoft.com/.../MS03-013.asp
http://www.microsoft.com/.../ms03-013.asp
- ---
Issue:
======
The Windows kernel is the core of the operating system. It provides
system level services such as device and memory management,
allocates processor time to processes and manages error handling.
There is a flaw in the way the kernel passes error messages to a
debugger. A vulnerability results because an attacker could write a
program to exploit this flaw and run code of their choice. An
attacker could exploit this vulnerability to take any action on the
system including deleting data, adding accounts with administrative
access, or reconfiguring the system.
For an attack to be successful, an attacker would need to be able
to logon interactively to the system, either at the console or
through a terminal session. Also, a successful attack would require
the introduction of code in order to exploit this vulnerability.
Because best practices recommends restricting the ability to logon
interactively on servers, this issue most directly affects client
systems and terminal servers.
Mitigating Factors:
====================
- - A successful attack requires the ability to logon
interactively to the target machine, either directly at the console
or through a terminal session.
- - Properly secured servers would be at little risk from this
vulnerability. Standard best practices recommend only allowing
trusted administrators to log onto such systems interactively;
without such privileges, an attacker could not exploit the
vulnerability. | Часовой пояс: GMT + 1 Похожие темы: | Тема |  | [ Опрос ] Девушки похожи или одна и та же? [На страницу: 1, 2, 3...5, 6, 7, 8, 9, 10] |  | Судьба Интернета - одна сигарета... [На страницу: 1, 2] |  | Может есть здесь хоть одна, которая н... [На страницу: 1, 2, 3...42, 43, 44, 45, 46, 47] |  | Еще одна ложь США? [На страницу: 1, 2, 3] |  | Кремль решил, что есть только одна ис... [На страницу: 1, 2, 3...21, 22, 23, 24, 25, 26] |  | Комп перегружается снова и снова,помо... [На страницу: 1, 2, 3, 4] |  | Во Львове Машам посоветовали "ех... [На страницу: 1, 2, 3, 4, 5, 6, 7] |  | Где можно купить дешёвый билет в Инди...
|  | На Марс, или Туда и Обратно [На страницу: 1, 2] |  | как туда добраться? Франкфурт/Маин [На страницу: 1, 2] | |