Featured Posts

FREE Kaspersky Security Suite CBE 10 Everyone may have read about Kaspersky Security Suite CBE Win7 that Ramakanth Posted about 4 months ago. CBE means Computer Bild Edition. This is the version of Kaspersky that is reserved free for registered...

Readmore

Download Divx Pro 7 for Free I think there is no need for introduction to Divx,here is a promo which will give you $19.99 worth Divx Pro 7 software for free. About Divx Pro 7 DivX® Pro 7 provides everything you need for...

Readmore

Ashampoo Burning Studio 2010 Advanced for Free Ashampoo Burning Studio 2010 Advanced is nothing but Ashampoo Burning Studio v9.24,which had some advanced features compared to Ashampoo Burning Studio 2010(v 9.10). This  free offer is set by Chip...

Readmore

2 Packs to Transform Windows 7 to Mac OS X Generally we will try to get applications (or whatever) what we don't have, although we had much better application compared to what we are trying, may be I think  it's human nature. I was obsessed...

Readmore

Advanced SystemCare Pro 3.6, Free 1 year License Yet another 1 year free offer  for IObit Advanced SystemCare Professional edition, last time Kowshik posted about the free Giveaway of  Advanced SystemCare Pro from Iobit itself. This time this free...

Readmore

  • Prev
  • Next

Microsoft issues Critical Security Patch for Windows

Posted on : 25-10-2008 | By : sai | In : Microsoft, Security, windows

0

Microsoft
Microsoft issued a emergency security patch  for a  “Critical” security flaw for  Windows 2000, Windows XP and Windows Server 2003 users on Thursday.

The vulnerability can result in a remote code execution, in which malicious attackers could take control of a user’s computer to launch code.

According to Microsoft’s bulletin, the vulnerability is found in Windows 2000 with Service Pack 4, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.

The most vulnerable versions of Windows are XP, 2000 and Server 2003. Vista and Server 2008 are also vulnerable, but not as badly. Microsoft considers the bug important enough to issue the patch immediately rather than waiting for their normal once-a-month patch Tuesday.


Microsoft issued a rare out-of-cycle patch for a vulnerability in the Windows Server service that handles remote procedure calls (RPC) that allows programmers to run code either locally or remotely. In issuing MS08-067, Microsoft warns “it is possible that this vulnerability could be used in the crafting of a wormable exploit.” Entitled “Vulnerability in Server Service Could Allow Remote Code Execution (958644)” the specific vulnerability has been assigned a National Vulnerability Database designation of CVE-2008-4250.

Microsoft normally issues patches on the second Tuesday of each month, which has been deemed Patch Tuesday. But out-of-cycle patches are not without precedent. Recent examples include the Windows Animated Cursor Remote Code Execution Vulnerability (April 2007), a vulnerability in Vector Markup Language (September 2006), and a vulnerability in the Graphics Rendering Engine (January 2006).

Making a Windows service not run all the time is called disabling and/or stopping. Stopping refers to the instance of the service currently running. Disabling means preventing it from ever starting again. Microsoft describes how to both stop and disable the Server service in Security Bulletin MS08-067. They also suggest doing the same to the Computer Browser service.

Anyone not sharing files and/or printers on a network should also turn off File and Printer Sharing for Microsoft Networks (the Windows XP name) on all network definitions. For example, on a laptop with both wired Ethernet networking and wireless Wi-Fi networking, File and Printer Sharing should be turned off in both network definitions.

If the Server and Computer Browser services are disabled, then some people might consider the last point (and the next) overkill. I think they are a good idea because it means two mistakes would have to be made to enable file and printer sharing as opposed to only one mistake.

For still more safety, look into how your firewall is configured to ensure that it does not allow incoming traffic on TCP port 139 or 445. Again, this is for someone not sharing files and printers. Firewall configuration varies widely, but if you are using the Windows firewall in XP, the exception for this is called “File and Printer sharing”.

Firewalls are the first line of defense against this type of problem. With that in mind, you may want to review the series of postings I did recently on adding a second router to a LAN to provide additional firewall protection to your most important computers.


Source:Cnet and USAToday

sai

Write a comment