Reported ASP.NET vulnerability and SBS 2003

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Alan Billharz [MSFT] (alanbill_at_online.microsoft.com)
Date: 10/15/04


Date: Thu, 14 Oct 2004 18:12:47 -0700

The Windows Small Business Server team would like to make all of our
customers aware of the recently reported ASP.NET vulnerability. The
official site for information about this issue for all Microsoft products is
located here: http://www.microsoft.com/security/incident/aspnet.mspx.

Some web components of the Windows Small Business Server 2003 product are
ASP.NET applications, including the CompanyWeb site, Remote Web Workplace,
and Outlook Mobile Access. Our investigation into this matter has not
revealed any specific vulnerability in the SBS 2003 ASP.NET applications;
however, as a purely precautionary measure, we recommend that all of our
Windows Small Business Server 2003 customers follow the instructions on the
following web site as soon as possible:

http://www.microsoft.com/downloads/details.aspx?familyid=DA77B852-DFA0-4631-AAF9-8BCC6C743026&displaylang=en

Thank you for your patience in this matter.

-Alan Billharz

SBS Program Management

-- 
This post is provided "AS IS" with no warranties, and confers no rights.


Relevant Pages

  • FYI New .wmf Security Vunerability... Microsoft Security Advisory (912840)
    ... Vulnerability in Graphics Rendering Engine Could Allow Remote Code ... malicious attacks on some customers involving a previously unknown security ... vulnerability in the Windows Meta File code area in the Windows ... Upon learning of the attacks, ...
    (microsoft.public.windows.server.sbs)
  • Re: Alert: MS03-019, Microsoft... wrong, again.
    ... Microsoft is wrong and misleading customers in this advisory. ... This Windows ... Media Service vulnerability is exploitable, as confirmed in the labs at ... I am not sure why Microsoft misidentified this vulnerability... ...
    (NT-Bugtraq)
  • Re: Reported ASP.NET vulnerability and SBS 2003
    ... > customers aware of the recently reported ASP.NET vulnerability. ... > Some web components of the Windows Small Business Server 2003 product are ...
    (microsoft.public.windows.server.sbs)
  • Alert: Microsoft Security Bulletin - MS02-060
    ... Customers should install Windows XP Service Pack 1 as a first option, and install the patch only as an interim measure. ... Customers who have applied Windows XP Service Pack 1 are at no risk from the vulnerability. ... For an attack to be successful, the user would need to visit a website under the attacker's control or receive an HTML e-mail from the attacker. ...
    (NT-Bugtraq)
  • Re: ISA2004 for SBS2003?
    ... > | include all of the service packs for the Windows Small Business Server ... > | Configure E-mail and Internet Connection Wizard, ... Customers tell us ...
    (microsoft.public.windows.server.sbs)