Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Windows Flaw Could Allow Attacks

XP, NT, and 2000 systems may be vulnerable to denial-of-service attacks.

Joris Evers, IDG News Service

  • 0 Yes
  • 0 No

A security bug in a network function of Windows NT 4, 2000, and XP can expose computers running those operating systems to a denial-of-service attack, Microsoft warned.

The flaw lies in Microsoft's implementation of a protocol called RPC, or Remote Procedure Call, that allows applications on a computer to call applications on another computer in a network.

An attack on the RPC service could cause the networking services on the system to fail, Microsoft said in security bulletin MS03-010 Wednesday.

An attack would be carried out by sending a malformed request to the RPC endpoint mapper, a service that holds connection information on all RPC processes on that machine.

Inside Access

The mapper listens on TCP/IP port 135, generally accessible from within a company network, but typically blocked for external traffic by a firewall, mitigating the risk of an attack from the Internet, Microsoft said.

A patch to fix the problem is available for Windows 2000 and Windows XP, but there is no patch for Windows NT 4.0 because of major changes in the RPC software since the release of Windows NT 4.0, according to Microsoft.

Windows NT 4.0 users should install a firewall and filter traffic on port 135, the vendor said.

  • Recommend this story?
  • 0 Yes
    0 No
 

Featured APC Accessories

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC Smart-UPS Loaded with cutting-edge features, unique battery life predictor, unbeatable on-line efficiencies and software agents allowing remote UPS monitoring. Get 10% off your entire kart purchase!

People who read this also read:

  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

Sponsored Links