Security 11021 Published by Philipp Esselbach 0

This vulnerability involves a new variant of the "File Fragment
Reading via .HTR" vulnerability, previous variants of which were
discussed in Microsoft Security Bulletins MS00-031 and MS00-044. Like
the original variants, this one could enable an attacker to request a
file in a way that would cause it to be processed by the .HTR ISAPI
extension. The result of doing this is that fragments of server-side
files like .ASP files could potentially be sent to the attacker.
There is no capability via the vulnerability to add, change or delete
files on the server, or to access a file without permissions.

Read more

Security 11021 Published by Philipp Esselbach 0

A parsing routine that is executed when PowerPoint 2000 opens files
contains an unchecked buffer. If an attacker inserted specially
chosen data into a PowerPoint file and could entice another user into
opening the file on his machine, the data would overrun the buffer,
causing either of two effects. In the less serious case, overrunning
the data would cause PowerPoint to fail, but wouldn´t have any other
effect. In the more serious case, overrunning the buffer could allow
the attacker to cause code of her choice to run on the user´s
machine. The code could take any action that the user himself could
take on the machine. Typically, this would enable the attacker´s code
to add, change or delete data, communicate with a remote server, or
take other actions.

A patch is available to fix this vulnerability. Please read Security Bulletin MS01-002 at: http://www.microsoft.com/technet/security/bulletin/ms01-002.asp for information on obtaining this patch.

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft:registered: Windows NT 4.0. The vulnerability could allow a malicious user to run a special program to disable an affected computer's network functionality.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-003.asp

Affected Software Versions

Microsoft Windows NT 4.0
Microsoft Windows NT 4.0, Terminal Server Edition

Patch Availability

Windows NT 4.0:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27272

Windows NT 4.0, Terminal Server Edition:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27291

Security 11021 Published by Philipp Esselbach 0

Issue:
======
A parsing routine that is executed when PowerPoint 2000 opens files contains an unchecked buffer. If an attacker inserted specially chosen data into a PowerPoint file and could entice another user into opening the file on his machine, the data would overrun the buffer, causing either of two effects. In the less serious case, overrunning the data would cause PowerPoint to fail, but wouldn´t have any other effect. In the more serious case, overrunning the buffer could allow the attacker to cause code of her choice to run on the user´s machine. The code could take any action that the user himself could take on the machine. Typically, this would enable the attacker´s code to add, change or delete data, communicate with a remote server, or take other actions.

Mitigating Factors:
===================
The user would need to be enticed into opening a malformed PowerPoint file

Patch Availability:
===================
A patch is available to fix this vulnerability. Please read Security Bulletin MS01-002 at: http://www.microsoft.com/technet/security/bulletin/ms01-002.asp for information on obtaining this patch.

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in a component that ships with Microsoft:registered: Office 2000, Windows 2000, and Windows Me. The vulnerability could, under certain circumstances, allow a malicious user to obtain cryptographically protected logon credentials from another user when requesting an Office document from a web server.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-001.asp

Affected Software Versions

Microsoft Office 2000
Microsoft Windows 2000
Microsoft Windows Me

Patch Availability

Microsoft Office 2000 (All Platforms):
http://officeupdate.microsoft.com/2000/downloaddetails/wecsec.htm
Microsoft Windows 2000 (Without Office 2000):
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=26889
Microsoft Windows Me (Without Office 2000):
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=26705

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in a component that ships as part of Microsoft:registered: Internet Information Server. The vulnerability could potentially allow an attacker to prevent an affected web server from providing useful service.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq00-100.asp

Affected Software Versions
Microsoft IIS 4.0
Microsoft IIS 5.0

Patch Availability
Microsoft IIS 5.0:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=26277

Microsoft IIS 4.0:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=26704

Note: The IIS 5.0 patch can be applied atop system running either Windows 2000 Gold or Service Pack 1. It will be included in Windows 2000 Service Pack 2.

Note: The IIS 4.0 patch can be applied atop system running Windows NT 4.0 Service Pack 6a or 5. It will be included in Windows NT 4.0 Service Pack 7.

Note: IIS users who have removed the FPSE are not affected by this vulnerability and do not need to take further action.

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability affecting Microsoft:registered: Windows:registered: 2000 domain controllers. The vulnerability could allow a malicious user with physical access to a domain controller to install malicious software on it.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq00-099.asp

Affected Software Versions

Microsoft Windows 2000 Server
Microsoft Windows 2000 Advanced Server

Note: Windows 2000 workstations are unaffected by this vulnerability.
Patch Availability

http://www.microsoft.com/Downloads/Release.asp?ReleaseID=26483

Note: On Windows 2000 Server and Advanced Server systems, this patch can be installed atop either the Gold version or Service Pack 1. It will be included in Windows Server and Advanced Server, Service Pack 2.

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in a component that ships as part of Microsoft:registered: Windows:registered: 2000. The vulnerability could a malicious web site operator to learn the names and properties of file and folders on the machine of a visiting user.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq00-098.asp

Affected Software Versions

Index Server 2.0
Indexing Service 3.0

Note: Index Server 2.0 ships as part of the Windows NT 4.0 Option Pack. Indexing Service 3.0 ships as part of all versions of Windows 2000.

Patch Availability

Indexing Service 3.0:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=26595

Note: As discussed in the FAQ, a patch has not been provided for Index Server 2.0, because this product should only be installed on web servers, which should never be used for browsing the Internet.

Note: This patch can be applied to systems running Windows 2000 Gold or Service Pack 1. It will be included in Windows 2000 Service Pack 3.