Microsoft Patches Four More Security Flaws
Software giant issues new security bulletins, one regarding a critical flaw in some versions of Windows.
Joris Evers, IDG News Service
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
Microsoft issued three security bulletins late Wednesday, offering patches for four recently discovered security vulnerabilities in several of its products. One hole in Windows NT, Windows 2000, and Windows XP was rated "critical" by the vendor.
The hole deemed "critical" is a buffer overrun flaw in the phone book of the Remote Access Service, a standard part of Windows NT 4.0, Windows 2000, and Windows XP. An attacker could gain full control over the machine or cause it to fail, Microsoft says in its advisory.
To carry out an attack, an attacker first has to change a RAS setting on the affected system, before connecting to the system using RAS. If the target system's settings restrict user access, it will not be at risk, Microsoft says. RAS is used for dial-up connections.
More Concerns
Another bulletin addresses a flaw in Internet Information Server versions 4.0 and 5.0, the Web server components of Windows NT 4.0 and Windows 2000. An attacker could run arbitrary code on the system by exploiting a flaw in software that supports HTR scripting, an older and largely obsolete scripting language, Microsoft says.
HTR has been part of IIS since version 2.0. It was never widely adopted because Active Server Pages, or ASP, introduced in IIS 4.0, became popular before HTR use could take off. Virtually the only use for HTR today is a Web-based NT password managed service, Microsoft says, adding that it has long recommended customers to disable HTR functionality and convert scripts that are needed to ASP. The IIS Lockdown Tool offered by Microsoft disables HTR by default.
A third security bulletin addresses two vulnerabilities in the SQLXML part of SQL Server 2000. SQLXML enables the transfer of XML data to and from SQL Server 2000. The most serious of the flaws could allow an attacker to take over the machine running the database, Microsoft says.
Pick Your Patch
More information on the RAS flaw can be found at: http://www.microsoft.com/technet/security/bulletin/MS02-029.asp.
More information on the flaw in IIS versions 4.0 and 5.0 can be found at: http://www.microsoft.com/technet/security/bulletin/MS02-028.asp.
More information on the SQLXML flaw can be found at: http://www.microsoft.com/technet/security/bulletin/MS02-030.asp.
Webcast: Going Green
Office Small Business 2007
Related Windows Articles
- Microsoft Warns of IE8 Lock-in With XP SP3 Microsoft Corp. yesterday warned users of Windows XP Service Pack 3 (SP3) that they won't be able to uninstall either the...
- Mainsoft Backs Visual Studio 2008 in Tools Cross-platform development products leverage Windows skills for deployment on Java, Linux, and Unix.
- Vista May Still Have Its Day Think Windows Vista is a hopeless dog and XP was always the cat's meow among users? Think again.
- One-Third of New PC Buyers Opt for XP New data finds 1 in 3 business PCs pass on Vista to get Windows XP under Microsoft's "downgrade" offer.
- Microsoft Updates a Patch Microsoft has re-released a security updates, saying the initial patch was incomplete.
Best Prices on Windows
Windows XP Professional w/SP2Price: $119.99
Windows Vista Ultimate w/SP1Price: $149.99
Windows XP Home Edition w/ SP2Price: $79.99
Windows Vista UltimatePrice: $160.91
Windows Vista Ultimate w/ SP1 (Full Product)Price: $183.48
Windows Vista Home PremiumPrice: $95.99
- CDW Virtualization Center What is Virtualization and how can it help you save money? Click here to find out.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...







