ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Microsoft urges urgent action on Windows security hole

Matt Loney ZDNet.co.uk

Published: 20 Jun 2001 10:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Systems running beta versions of Microsoft Windows XP, as well as production versions of Windows 2000 Professional, Server, Advanced Server and Datacenter Server have a bug that allows a remote intruder to run any code on the victim machine, according to CERT, the pre-eminent reporting centre for Internet security problems.

Systems running Microsoft Windows NT 4.0 with IIS 4.0 or IIS 5.0 enabled are also affected by the vulnerability, which gives an intruder complete control over the target machine.

Microsoft said the problem is a "serious vulnerability", and said it is urging all customers to "take action immediately".

While patches are available for Windows NT 4.0 and for Windows 2000 systems, there is no patch available for the Windows XP beta. CERT is advising Windows XP users to "upgrade to a newer version of the software when it becomes available".

According to CERT, specific technical details on how to create an exploit are publicly available for this vulnerability. "System administrators should apply fixes or workarounds on affected systems as soon as possible," said the organisation in its alert this morning.

The problem, which was discovered by eEye Digital Security, stems from a remotely exploitable buffer overflow in one of the ISAPI extensions installed with most versions of IIS 4.0 and 5.0. ISAPI extensions are dynamic link libraries (dlls) that provide extended functionality. The dll causing the problem is called idq.dll, which provides support for administrative scripts (.ida files) and Internet Data Queries (.idq files).

According to Microsoft, an attacker who could establish a web session with a server on which idq.dll is installed "could conduct a buffer overrun attack and execute code on the web server... giving the attacker complete control of the server and allow him to take any desired action on it".

The company said that customers who cannot install the patch can protect their systems by removing the script mappings for .idq and .ida files via the Internet Services Manager in IIS. But even this can cause problems because it is possible for these mappings to be automatically reinstated if additional system components are added or removed. Because of this, Microsoft recommends that all customers using IIS install the patch, even if the script mappings have been removed.

The patch for Windows NT 4.0 is available here, while the patch for Windows 2000 Professional, Server, and Advanced Server can be found here. CERT said that users of Windows 2000 Datacenter Server software should contact the company that supplied the hardware for patches.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
27 out of 57 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Flash Developer- Digital Agency

Award winning Soho-based integrated agency are looking for a talented Senior Action script Developer. Essential skills: * Flash CS2/3 + Action Script ...

FLASH DEVELOPER - ActionScript - Berkshire - 30-33k + Benefits

To perform this role you will require a thorough understanding of Action Script 2/3 and be an expert in writing .AS files. Key Words: Flash ...

IMMEDIATE DESKTOP SUPPORT OPPORTUNITY WEST LONDON 25-30K

IIS experience is also desirable, as is SQL Server. MS Administration, data Recovery and Antivirus Procedures, Telephony Systems, MS 2003 & NT, MS ...

Discussions

319762 319762

Eve of Distraction

Saturday 26 July 2008, 4:37 AM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal