ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft patches new security flaws

Ian Fried, CNET CNET News.com

Published: 29 May 2003 07:47 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Wednesday issued a pair of security alerts addressing potential flaws that could make its software vulnerable to attackers.

The higher-rated of the two bulletins includes a patch that fixes four separate vulnerabilities in Microsoft's Internet Information Services (IIS) software. That alert, rated "important", addresses vulnerabilities that could make servers running the software vulnerable to a denial-of-service attack.

"We definitely want everyone who is running IIS 4.0, 5.0 and 5.1 to install the patch," said Microsoft program manager Stephen Toulouse. However, IIS 6 and Microsoft Windows Server 2003 are not affected by the flaws, he added.

A second bulletin, rated "moderate", addresses a vulnerability in Windows Media Services that, if exploited, could result in a denial-of-service attack. The bulletins are Microsoft's 18th and 19th security warnings of the year.

Of the four issues addressed in the combination patch, the most serious vulnerability is one in the WebDav service that IIS uses for authoring. If exploited, the flaw could cause a server running IIS to stop responding to requests. That vulnerability exists in versions 5.0 and 5.1 of IIS, but not in version 4.0.

Two other flaws addressed by the combination patch are rated as moderate. One could lead to a denial of service, while another could allow malicious code to be run through what is known as a "buffer overrun". However, to be exploited, both vulnerabilities require an attacker to first upload a specific page to a Web page.

As for Microsoft's second bulletin, which addresses Windows Media Services, a flaw in one of the files associated with that software could allow someone to cause an IIS server to stop responding.

Microsoft has taken a number of steps in recent months to try to convince more information technology managers to install its security patches. The company has set up separate email alert systems for corporate IT managers and for consumers as well as a toll-free number, should customers encounter problems with any of Microsoft's patches.

Toulouse said that while Microsoft tries to work quickly to address problems, it spends as much time as possible testing its fixes to make sure new flaws are not introduced.

"We aren't satisfied until everyone has the patch installed," he said. "We've done a variety of things to try and communicate as broadly as we can to our customers that they need to install these updates."

In addition to the two new bulletins, Microsoft updated two existing alerts, issuing a new patch for one vulnerability and updating an existing patch for a different flaw. On Tuesday, the company withdrew a security update for Windows XP, saying that it switched off Internet connections for some of those who had downloaded the patch.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
53 out of 119 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Architecture Manager (Technical Architect) North West

Architecture Manager delivers the following responsibilities through the team he manages - Delivering Infrastructure solution designs in response to ...

UK Business Consultant - Asset Management Software

My client is a specialist provider of technology solutions to hedge funds and other Investment Managers. You will be working directly with ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments