Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft:registered: Windows Media Player 7. This vulnerability could potentially enable a malicious user to cause a program of his choice to run on another user's computer.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-010.asp

Affected Software Versions
Microsoft Windows Media Player 7

Patch Availability
Microsoft Windows Media Player 7:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27961

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft:registered: Windows NT:registered: 4.0 servers that provide secure remote sessions. The vulnerability could allow an attacker to prevent an affected machine from providing useful service.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-009.asp

Affected Software Versions
Microsoft Windows NT 4.0 Server
Microsoft Windows NT 4.0 Server, Enterprise Edition
Microsoft Windows NT 4.0 Server, Terminal Server Edition

Patch Availability
Windows NT 4.0 Server and Windows NT 4.0 Server, Enterprise Edition:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27836
Windows NT 4.0 Server, Terminal Server Edition:
To be released shortly

Note: This patch can be applied to systems running Windows NT 4.0 Service Pack 6a. The fix will be included in Windows NT 4.0 Service Pack 7.

Security 11021 Published by Philipp Esselbach 0

A virus posing as a photo of Russian tennis player Anna Kournikova spread aggressively on Monday, as major security companies rushed to update their antivirus software to detect the fast-spreading e-mail virus.

Read more

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft:registered: Windows:registered: 2000. The vulnerability could, under certain conditions, allow an attacker to gain complete control over an affected machine.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-007.asp

Affected Software Versions
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows 2000 Advanced Server

Patch Availability
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27526

Note: This patch can be installed on systems running Windows 2000 Gold, Service Pack 1, and Service Pack 2. It will be included in Service Pack 3.

Security 11021 Published by Philipp Esselbach 0

The Web Client Security Update for Office 2000 protects you from a vulnerability in Office 2000 that can allow login information to be sent over the Internet. Malicious Web site operators could deceive users into browsing to a Web page or server that captures login information without permission or verification of credentials from the user. This update prevents user credentials from being sent unless users grant express permission consistent with their browser settings.

Download

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft:registered: Windows NT 4.0. The vulnerability could allow a locally logged on user to grant herself administrator level privileges.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-008.asp

Affected Software Versions

Microsoft Windows NT 4.0 Workstation
Microsoft Windows NT 4.0 Server
Microsoft Windows NT 4.0 Server, Enterprise Edition
Microsoft Windows NT 4.0 Server, Terminal Server Edition

Patch Availability

Microsoft Windows NT 4.0 Workstation, Server, and Enterprise Edition:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27804
Microsoft Windows NT 4.0 Server, Terminal Server Edition:
(will be available shortly)

NOTE This patch may be applied to Windows NT 4.0 Service Pack 6a.

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a patch that eliminates a security vulnerability in Microsoft:registered: Windows:registered: 2000. The vulnerability could, under certain conditions, allow an attacker to gain complete control over an affected machine.

Affected Software Versions
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows 2000 Advanced Server

Patch Availability
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27526

Note: This patch can be installed on systems running Windows 2000 Gold, Service Pack 1, and Service Pack 2. It will be included in Service Pack 3.

Security 11021 Published by Philipp Esselbach 0

MooSoft has released a trojan definitions database update for "The Cleaner".

Database v3204, 2885 trojan definitions.
------------------------
Added Double Fever
Added Gift
Added iDEMON
Added Last2000
Added RAID

Updated BioNet
Updated Infector
Updated Latinus
Updated MoSucker
Updated VBS.PlanColumbia
Updated Y3K

To update to the latest database, run MooLive: Start->Programs->The
Cleaner->MooLive

Security 11021 Published by Philipp Esselbach 0

The implementation of the Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not correctly handle a particular series of data packets. If such a series of packets were received by an affected server, it would cause the server to fail. The server could be put back into normal service by rebooting it, but any work in progress at the time of the attack would be lost.

It would not be necessary for an attacker to be able to start a session with an affected server in order to exploit this vulnerability - he would only need the ability to send the correct series of packets to the RDP port on the server. The specific sequence of data packets involved in this vulnerability cannot be generated as part of a legitimate terminal server session. Windows NT 4.0 terminal servers are not affected by this vulnerability.

Read more/Download

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a tool and patch that allow customers to diagnose and eliminate the effects of anomalies in the packaging of hotfixes for English language versions of Microsoft:registered: Windows 2000. Under certain circumstances, these anomalies could cause the removal of some hotfixes, which could include some security patches, from a Windows 2000 system.

Frequently asked questions regarding this vulnerability and the patch can be found at http://www.microsoft.com/technet/security/bulletin/fq01-005.asp

Affected Software Versions

Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows 2000 Advanced Server

Patch Availability

Diagnostic tool:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27333
Microsoft Windows 2000 Gold:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27332
Microsoft Windows 2000 SP1:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27330