ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft warns of new server vulnerabilities

Matthew Broersma ZDNet.co.uk

Published: 25 Jul 2002 16:17 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has warned of several newly discovered security holes in SQL Server, Microsoft Desktop Engine and Exchange software, the most serious of which could give an attacker control over an installation of SQL Server.

The software company also issued a corrected version of last month's cumulative patch for Windows Media Player, which left out some bug fixes, although it said that this mistake did not reduce the effectiveness of the original patch. The new Windows Media Player patch is available here.

Two of the exploits were serious enough for Microsoft to class as "critical" -- its most severe rating -- because they allow artibrary code to be executed on SQL Server 2000. The exploits in question involve sending a carefully crafted packet to the SQL Server Resolution Service, which exists to help coordinate multiple installations of the server on the same machine.

The attack can cause a buffer overrun in the system memory, allowing a skilled attacker to run code in the server's security context. However, Microsoft said that by default, SQL Server 2000 runs as a Domain User, which has limited priveleges.

This attack may be easily prevented by blocking port 1434, Microsoft said.

Another bug in the Resolution Service would allow a denial-of-service attack by causing two SQL Server 2000 systems to enter into an endless communications loop, significantly degrading performance. The warning and patch for all three problems is here.

Microsoft also warned of two vulnerabilities that affect both SQL Server 2000 and Microsoft Desktop Engine, allowing an attacker to run code on the server, for which an explanation and patch are available here.

The company said that Exchange is vulnerable to a buffer overflow attack when responding to an SMTP client's EHLO command. The alert and patch are available here.

Microsoft has vowed to make security its top priority, even if it means delaying important products. However, industry experts say that Microsoft's plan can only be effective as a long-term commitment.

A more immediate response may have been achieved via new legislation. A recent security survey found that the number of successful attacks on Windows and government servers had dropped off steeply, following an amendment to the US's Cyber Security Enhancement Act, which gives life imprisonment to hackers who put lives at risk.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
72 out of 111 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

C# Developer C#, ASP.NET, SQL Server, SharePoint - Oxfordshire REF:2103

C# Developer C#, ASP.NET, SQL Server, SharePoint - Abingdon, Oxfordshire, South East UK - REF:2103 Would you like to hone your C# / ASP.NET / SQL ...

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

Other main functions of the role are troubleshooting & resolving cross platform message flow related issues, problem resolution & estate & patch ...

Applications Support, ITIL, SQL Server, ASP, .NET, C#, W. Yorkshire

Other duties include project work, training and development of the helpdesk staff, release and patch management, document processes and procedures ...

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains