latest Microsoft Windows Security Flaws

From: Daeron (doug_mentohl_at_yahoo.co.uk)
Date: 02/10/04


Date: 10 Feb 2004 14:21:04 -0800

Microsoft Warns on Windows Security Flaws
Ted Bridis Feb 10 2004 Washington (AP) -

[..]

Microsoft, which learned about the flaws more than six months ago from
researchers, said the only protective solution was to apply a
repairing patch it offered on its Web site. It assessed the threat to
computer users as "critical," its highest rating.

[..]

"This is one of the most serious Microsoft vulnerabilities ever
released," said Marc Maiffret of eEye Digital Security Inc. of Aliso
Viejo, Calif., which discovered the new Windows flaws.

"The breadth of systems affected is probably the largest ever. This is
something that will let you get into Internet servers, internal
networks, pretty much any system."

Maiffret said some computer systems that control critically important
power or water utilities were vulnerable.

[..]

The problems affected a technology in the newest versions of Windows
known as "abstract syntax notation," a way to share data across
different computers. Some of Microsoft's built-in security features -
such as its Kerberos cryptography system - rely on the flawed
software.

[..]

http://apnews.myway.com//article/20040210/D80KJ01G1.html



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #242
    ... MICROSOFT VULNERABILITY SUMMARY ... PostNuke Blocks Module Directory Traversal Vulnerability ... Groove Networks Groove Virtual Office COM Object Security By... ... The Microsoft Windows IPV6 TCP/IP stack is prone to a "loopback" condition initiated by sending a TCP packet with the "SYN" flag set and the source address and port spoofed to equal the destination source and port. ...
    (Focus-Microsoft)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)