Contribute  :  Advanced Search  :  Site Statistics  :  Directory  :  Calendar  :  Links  :  Polls  :  About Us  :  The Staff  
Topsight.net Discussions on computers and beyond
Welcome to Topsight.net
Thursday, May 15 2008 @ 11:23 PM EDT
   

Multiple Vulnerabilities in Microsoft RPC Service

SecurityFrom Internet security systems: Synopsis:

Microsoft has released a security bulletin (MS03-039) detailing three distinct vulnerabilities in the Windows RPC (Remote Procedure Call) functionality. One of the vulnerabilities disclosed is a denial of service condition, or DoS. The additional two vulnerabilities are buffer overflow vulnerabilities, and are significantly more serious in nature.

Impact:

The flaws described in this advisory are similar in nature and scope as the flaw described in Microsoft Security Bulletin MS03-026, and the ISS Security Alert titled, "Flaw in Microsoft Windows RPC Implementation". The new DoS vulnerability was disclosed by a hacking group in China on July 25, 2003, and functional exploit code is already in use on the Internet. The additional two new issues may allow remote attackers to compromise and gain complete control of vulnerable systems.

The MS Blast and Nachi worms propagated via the vulnerabilities disclosed in MS03-26, and X-Force believes that there is significant potential for the creation and propagation of a serious Internet worm that exploits one or both of the newly disclosed RPC vulnerabilities.

See complete report from Internet Security Systems here
Get the patch from microsoft here

Multiple Vulnerabilities in Microsoft RPC Service | 2 comments | Create New Account
The following comments are owned by whomever posted them. This site is not responsible for what they say.
Multiple Vulnerabilities in Microsoft RPC Service
Authored by: logikal on Thursday, September 11 2003 @ 12:12 AM EDT
Is a new Windows XP worm season coming?