ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft finds 'critical' flaw in Phonebook

Rachel Lebihan ZDNet Australia

Published: 13 Jun 2002 08:41 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has alerted users to a "critical" flaw in the Remote Access Service (RAS) Phonebook that could cause a system failure, or allow attackers to run code on vulnerable systems with LocalSystem privileges.

According to a security alert issued by Australian computer security company itSecure, RAS provides dial-up connections between computers and networks over phone lines and the RAS phonebook is used to store information about telephone numbers, security, and network settings used to dial-up remote systems.

The flaw in this instance is a phonebook value that is not properly checked and susceptible to a buffer overrun.

Affected software includes Microsoft Windows NT 4.0, Microsoft NT 4.0 Terminal Server Edition, Windows 2000, Windows XP, Routing and Remote Access Server (RRAS), all of which include a RAS phonebook.

The software maker has issued a critical security bulletin and has released patches to fix the vulnerability.

According to itSecure chief security officer Raul Wegat, anyone who uses their computer to connect to a network such as the Internet, a VPN, office network via dialup, for example, would be vulnerable. But he added: "We're currently not aware of any exploit tools in circulation."

ItSecure has tagged the vulnerability as "very severe".

"We rate software vulnerabilities based the vendors rating as well as our evaluation of the impact the vulnerability may have. We often rate Alerts higher than vendors due to vendors' propensity to 'under-rate' the problem," Wegat said.

The world's dominant software vendor posted two other technical advisories on Wednesday night. The first alerts users to a vulnerability in Microsoft SQLXML that could allow attackers to execute code of their choice on the Microsoft Internet Information Services (IIS) Server, or execute a script on a user's computer with a higher privilege than is allowed.

The other alert concerns a new vulnerability in IIS Servers that could allow an attacker to execute code of his or her choice on the victim server. Both carry a "moderate" itSecure risk assessment.

"The main concern with these three alerts, as with all Microsoft vulnerabilities, is that with the prolific use of Microsoft products their software development process, particularly testing, needs to improve," Wegat said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
53 out of 95 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Please educate your clients!

This extremely short post appeared following a meeting with a decision maker of a potential client. During the conversation I realized that this highly respected and well paid top manager... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains