Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Microsoft Security Bulletin - Vulnerability in Server Service Could Allow Remote Code Execution
Microsoft ^ | 2008-10-23 | Microsoft

Posted on 10/23/2008 10:34:26 AM PDT by justlurking

Executive Summary

This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code. It is possible that this vulnerability could be used in the crafting of a wormable exploit. Firewall best practices and standard default firewall configurations can help protect network resources from attacks that originate outside the enterprise perimeter.

This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, and rated Important for all supported editions of Windows Vista and Windows Server 2008. For more information, see the subsection, Affected and Non-Affected Software, in this section.

The security update addresses the vulnerability by correcting the way that the Server service handles RPC requests. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.

Recommendation. Microsoft recommends that customers apply the update immediately.

Known Issues. None



TOPICS: Computers/Internet
KEYWORDS:
Run Windows update and apply the patch as soon as possible. This is a very serious security hole and there are reportedly already exploits running about in the wild.
1 posted on 10/23/2008 10:34:27 AM PDT by justlurking
[ Post Reply | Private Reply | View Replies]

To: justlurking

A security hole in Windows? I’m shocked, shocked I tell ya!!


2 posted on 10/23/2008 10:39:10 AM PDT by Oshkalaboomboom
[ Post Reply | Private Reply | To 1 | View Replies]

To: Oshkalaboomboom

They exist in OSX and Linux too.


3 posted on 10/23/2008 10:44:01 AM PDT by VanDeKoik
[ Post Reply | Private Reply | To 2 | View Replies]

To: justlurking

If someone ever figures out how to crack the Windows Update feature, we could have a real mess on our hands.


4 posted on 10/23/2008 10:44:58 AM PDT by CatOwner
[ Post Reply | Private Reply | To 1 | View Replies]

To: justlurking; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

5 posted on 10/23/2008 12:29:07 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: justlurking

Done, thanks!


6 posted on 10/23/2008 12:46:16 PM PDT by freebird5850 (O-Bomb-a, the sleeper cell that almost slipped by all of us.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CatOwner
If someone ever figures out how to crack the Windows Update feature, we could have a real mess on our hands.
Yeah. Or OS X or any software update system . . .

7 posted on 10/23/2008 2:30:27 PM PDT by conservatism_IS_compassion (We come to FR to pool our skepticism.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: justlurking

This one is huge. We’ve got folks from our windows groups running around today like their hair is on fire.


8 posted on 10/23/2008 3:04:56 PM PDT by zeugma (Mark Steyn For Global Dictator!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: justlurking

Sorry, I quit downloading XP updates when Microsoft trashed my ability to get on the internet with one of their ‘improvements’. Seems they didn’t like folks using ZoneAlarm.


9 posted on 10/23/2008 9:19:42 PM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson