ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Microsoft patches Windows NT WebDAV flaw

Published: 25 Apr 2003 08:11 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Thursday released an update for Windows NT that fixes the critical vulnerability that allowed an intruder to sneak onto a military server running Windows 2000.

The software giant issued the patch for Windows 2000 in less than a week after learning of the problem, but decided to do its standard analysis to check whether the rest of its operating systems were vulnerable. The advisory and software patch for Windows NT are the result of the five-week process, said Stephen Toulouse, program manager for Microsoft's security response centre.

"The reason we really didn't have an NT fix is because we had to ship the bulletin faster than we normally do," Toulouse said. "We turned around the critical Windows 2000 fix in five or six days. Once we got the Windows 2000 fix out, we resumed our process."

The flaw could allow an attacker to gain total control of an Internet-accessible computer running unpatched versions of the Windows 2000 and NT operating systems, according to the revised advisory posted to Microsoft's site.

The original flaw allowed an online attacker to take control of a military server last March by using the World Wide Web Distributed Authoring and Version (WebDAV) component of Microsoft's flagship Web server software, Internet Information Services (IIS) Server 5.0.

The vulnerability took the software giant's security group by surprise because a security researcher wasn't the source of information about the problem. Normally, a researcher or hacker who finds a vulnerability will announce the details publicly or to the software's creator. Instead, the attack on the military server was Microsoft's first notice that the flaw existed.

In a paper published a week after Microsoft released the patch, David Litchfield, a security researcher at UK-based Next-Generation Security Software, stated that the flaw could be exploited using other operating system components, not just WebDAV.

"The problem is much wider in scope than machines running IIS," Litchfield wrote in the paper.

Both Next Generation Security Software and Microsoft recommend that all Windows 2000 and NT users apply the patch. Windows XP and Windows Server 2003 are not affected by the flaw.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
70 out of 150 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Trade Floor Support at Top Global IB!!! + Career Progression!

You must have desktop/trade floor experience in a financial company, as well as Market Data, working knowledge of Blackberries, and strong Windows ...

Websphere IT Specialist / Architect

Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Websphere IT ...

IT Manager - hands on - Leics - Up to 30,000

The role will be providing all IT support to 2 Leicestershire based sites covering hardware and software installation and maintenance, maintenance of ...

Discussions

davidparry davidparry

Rugged or Heavy Duty?

Sunday 11 May 2008, 9:50 AM

1 comment
dotancohen dotancohen

Just install Ubuntu!

Saturday 10 May 2008, 6:57 PM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal