Featured Posts

FREE Kaspersky Security Suite CBE Win7 or KIS 2010... I know & I think every one know that kaspersky is top rated security solution compared to all other security products. Previously we shared several kaspersky Promotions and one (26) KIS 2010 License...

Readmore

Download Ashampoo Burning Studio 9.10 For Free Previously( on Sept 22)  we shared promo for Ashampoo Burning Studio Advanced,now we are here with another Ashampoo  promo which will give you Free full version license key for Ashampoo Burning...

Readmore

Download Divx Pro 7 for Free I think there is no need for introduction to Divx,here is a promo which will give you $19.99 worth Divx Pro 7 software for free. About Divx Pro 7 DivX® Pro 7 provides everything you need for...

Readmore

Free 60 days Kaspersky Internet Security 2009 License This promo doesn't requires any registration...e.t.c, just click this  link http://www.kasperskyusa.com/custom/nasba/kis8.0.0.506en.exe and download the installation file. A activation key is already...

Readmore

Free 3 months F-Secure Internet Security 2010 License Now F-Secure Internet Security 2010 was officially launched, so we are sharing a promo, that will give you 3 months F-Secure Internet Security 2010 License for free. About F-Secure Internet Security...

Readmore

Techno 360 Rss

Microsoft issues Critical Security Patch for Windows

Posted by sai | Posted in Microsoft, Security, windows | Posted on 25-10-2008

0

Microsoft
Microsoft issued a emergency security patch  for a  “Critical” security flaw for  Windows 2000, Windows XP and Windows Server 2003 users on Thursday.

The vulnerability can result in a remote code execution, in which malicious attackers could take control of a user’s computer to launch code.

According to Microsoft’s bulletin, the vulnerability is found in Windows 2000 with Service Pack 4, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.

The most vulnerable versions of Windows are XP, 2000 and Server 2003. Vista and Server 2008 are also vulnerable, but not as badly. Microsoft considers the bug important enough to issue the patch immediately rather than waiting for their normal once-a-month patch Tuesday.


Microsoft issued a rare out-of-cycle patch for a vulnerability in the Windows Server service that handles remote procedure calls (RPC) that allows programmers to run code either locally or remotely. In issuing MS08-067, Microsoft warns “it is possible that this vulnerability could be used in the crafting of a wormable exploit.” Entitled “Vulnerability in Server Service Could Allow Remote Code Execution (958644)” the specific vulnerability has been assigned a National Vulnerability Database designation of CVE-2008-4250.

Microsoft normally issues patches on the second Tuesday of each month, which has been deemed Patch Tuesday. But out-of-cycle patches are not without precedent. Recent examples include the Windows Animated Cursor Remote Code Execution Vulnerability (April 2007), a vulnerability in Vector Markup Language (September 2006), and a vulnerability in the Graphics Rendering Engine (January 2006).

Making a Windows service not run all the time is called disabling and/or stopping. Stopping refers to the instance of the service currently running. Disabling means preventing it from ever starting again. Microsoft describes how to both stop and disable the Server service in Security Bulletin MS08-067. They also suggest doing the same to the Computer Browser service.

Anyone not sharing files and/or printers on a network should also turn off File and Printer Sharing for Microsoft Networks (the Windows XP name) on all network definitions. For example, on a laptop with both wired Ethernet networking and wireless Wi-Fi networking, File and Printer Sharing should be turned off in both network definitions.

If the Server and Computer Browser services are disabled, then some people might consider the last point (and the next) overkill. I think they are a good idea because it means two mistakes would have to be made to enable file and printer sharing as opposed to only one mistake.

For still more safety, look into how your firewall is configured to ensure that it does not allow incoming traffic on TCP port 139 or 445. Again, this is for someone not sharing files and printers. Firewall configuration varies widely, but if you are using the Windows firewall in XP, the exception for this is called “File and Printer sharing”.

Firewalls are the first line of defense against this type of problem. With that in mind, you may want to review the series of postings I did recently on adding a second router to a LAN to provide additional firewall protection to your most important computers.


Source:Cnet and USAToday

Twitter It!

Related posts:

  1. Microsoft Patches IE security hole used by chinese hackers
  2. Patch to Fix Media Player 12 / Windows 7 MP3 File Corruption Issues
  3. Microsoft Announces Windows Azure, Cloud-Based OS
  4. New security breach in IE
  5. Another Critical vulnerability Found in Firefox 3.5

Buzz it!

Write a comment

Spam Protection by WP-SpamFree