Security 10941 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft(r) Windows 2000. The vulnerability could allow a malicious user to cause a Denial of Service on a Windows 2000 computer.

Frequently asked questions regarding this vulnerability and the patch can be found at
http://www.microsoft.com/technet/security/bulletin/fq00-066.asp

Affected Software Versions
===========================
- Microsoft Windows 2000 All Versions

Note: Microsoft Windows NT 4.0 is not affected by this vulnerability.

Patch Availability
==================
Microsoft Windows 2000:
- http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24229

- This patch will also be included in the next Service Pack for Windows 2000 -- it can be applied to a computer with or without Service Pack 1.

Security 10941 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security
vulnerability in Microsoft(r) Windows 2000. The vulnerability could
allow a user logged onto a Windows 2000 machine from the keyboard to
become an administrator on the machine.

Frequently asked questions regarding this vulnerability and the patch
can be found at
http://www.microsoft.com/technet/security/bulletin/fq00-065.asp

Affected Software Versions
==========================
- Microsoft Windows 2000

Patch Availability
==================
- Microsoft Windows 2000:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24200

Security 10941 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security
vulnerability in Microsoft(r) Windows Media(tm) Services. The
vulnerability could allow a malicious user to prevent an affected
server from providing useful service.

Frequently asked questions regarding this vulnerability and the patch
can be found at
http://www.microsoft.com/technet/security/bulletin/fq00-064.asp

Affected Software Versions
==========================
- Microsoft Windows Media Services 4.0
- Microsoft Windows Media Services 4.1

Patch Availability
==================
- Microsoft Windows Media Services 4.1:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24167

Security 10941 Published by Philipp Esselbach 0

The discovery of the first virus to exploit the file stream feature of Windows 2000 to infect PCs has provoked a fierce debate about the adequacy of antivirus software in combating such infection.

The W2K/Streams virus, an executable file virus that only affects Windows 2000 systems, has been described by antivirus vendors as more of interest as a ´proof of concept´ than a threat. Antivirus vendors have, however, updated their software to detect the virus.

Read more

Security 10941 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security
vulnerability in Microsoft(r) Internet Information Server (IIS). The
vulnerability could enable a malicious user to prevent an affected
web server from providing useful service.

Frequently asked questions regarding this vulnerability and the patch
can be found at
http://www.microsoft.com/technet/security/bulletin/fq00-063.asp

Affected Software Versions
==========================
- Microsoft Internet Information Server 4.0

Note: As noted above in "Issue", the root cause of this vulnerability
lies in Windows NT 4.0, and Microsoft recommends that customers
using Windows NT 4.0 consider applying the patch.

Patch Availability
==================
- Microsoft Windows NT 4.0 Workstation, Server and Server,
Enterprise Edition:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24079
- Microsoft Windows NT 4.0 Server, Terminal Server Edition: To be
released shortly

Security 10941 Published by Philipp Esselbach 0

Microsoft has released a Hotfix Checking Tool for IIS 5.0.

This tool enables IIS 5.0 administrators to to ensure that their servers are up to date on all security patches. The tool can be run continuously or periodically, against the local machine or a remote one, using either a database on the Microsoft web site or a locally-hosted copy. When the tool finds a patch that hasn´t been installed, it can display or dialogue or write a warning to the event log.

Download