Advertisement
Promo

Online business Toolkit

Microsoft warns of new server vulnerabilities

Matthew Broersma ZDNet.co.uk

Published: 25 Jul 2002 16:17 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has warned of several newly discovered security holes in SQL Server, Microsoft Desktop Engine and Exchange software, the most serious of which could give an attacker control over an installation of SQL Server.

The software company also issued a corrected version of last month's cumulative patch for Windows Media Player, which left out some bug fixes, although it said that this mistake did not reduce the effectiveness of the original patch. The new Windows Media Player patch is available here.

Two of the exploits were serious enough for Microsoft to class as "critical" -- its most severe rating -- because they allow artibrary code to be executed on SQL Server 2000. The exploits in question involve sending a carefully crafted packet to the SQL Server Resolution Service, which exists to help coordinate multiple installations of the server on the same machine.

The attack can cause a buffer overrun in the system memory, allowing a skilled attacker to run code in the server's security context. However, Microsoft said that by default, SQL Server 2000 runs as a Domain User, which has limited priveleges.

This attack may be easily prevented by blocking port 1434, Microsoft said.

Another bug in the Resolution Service would allow a denial-of-service attack by causing two SQL Server 2000 systems to enter into an endless communications loop, significantly degrading performance. The warning and patch for all three problems is here.

Microsoft also warned of two vulnerabilities that affect both SQL Server 2000 and Microsoft Desktop Engine, allowing an attacker to run code on the server, for which an explanation and patch are available here.

The company said that Exchange is vulnerable to a buffer overflow attack when responding to an SMTP client's EHLO command. The alert and patch are available here.

Microsoft has vowed to make security its top priority, even if it means delaying important products. However, industry experts say that Microsoft's plan can only be effective as a long-term commitment.

A more immediate response may have been achieved via new legislation. A recent security survey found that the number of successful attacks on Windows and government servers had dropped off steeply, following an amendment to the US's Cyber Security Enhancement Act, which gives life imprisonment to hackers who put lives at risk.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
72 out of 111 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

Post a comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters