OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Microsoft Product Security (secnotifMICROSOFT.COM)
Date: Mon Oct 22 2001 - 14:34:18 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    The following is a Security Bulletin from the Microsoft Product Security
    Notification Service.

    Please do not reply to this message, as it was sent from an unattended
    mailbox.
                        ********************************

    -----BEGIN PGP SIGNED MESSAGE-----

    - -
    - ----------------------------------------------------------------------
    Title: Invalid RDP Data can Cause Terminal Service Failure
    Date: 18 October 2001
    Revised: 22 October 2001 (version 2.0)
    Software: Windows NT 4.0 Server, Terminal Server Edition,
                Windows 2000 Server and Advanced Server
    Impact: Denial of service
    Max Risk: Moderate
    Bulletin: MS01-052

    Microsoft encourages customers to review the Security Bulletin at:
    http://www.microsoft.com/technet/security/bulletin/MS01-052.asp.
    - - -
    - -
    - ----------------------------------------------------------------------

    Reason for Revision:
    ====================
    On October 18, 2001 Microsoft released the original version of this
    bulletin. On October 19, 2001, an issue was identified with the
    Windows 2000 patch. The patch was withdrawn so that it could be
    updated and re-released. On October 22, 2001 the updated patch
    and bulletin were posted.

    We recommend that customers who installed the original version
    of the Windows 2000 patch install the updated version.
     
    Issue:
    ======
    The implementation of the Remote Data Protocol (RDP) in the terminal
    service in Windows NT 4.0 and Windows 2000 does not correctly handle
    a particular series of data packets. If such a series of packets
    were received by an affected server, it would cause the server to
    fail. The server could be put back into normal service by rebooting
    it, but any work in progress at the time of the attack would be
    lost.

    It would not be necessary for an attacker to be able to start a
    session with an affected server in order to exploit this
    vulnerability - the only prerequisite would be the need to be able
    to send the correct series of packets to the RDP port on the server.

    Mitigating Factors:
    ====================
     - There is no capability to breach the security of a terminal
       server session via this vulnerability, or to add, change or
       delete data on the server. It is a denial of service
       vulnerability only.
     - The specific sequence of data packets involved in this
       vulnerability cannot be generated as part of a legitimate
       terminal server session.

    Risk Rating:
    ============
     - Internet systems: Low
     - Intranet systems: Moderate
     - Client systems: None

    Patch Availability:
    ===================
     - A patch is available to fix this vulnerability. Please read the
       Security Bulletin at
       http://www.microsoft.com/technet/security/bulletin/ms01-052.asp
       for information on obtaining this patch.

    Acknowledgment:
    ===============
     - Luciano Martins of Deloitte & Touche Argentina
       (http://www.deloitte.com.ar)

    - - -
    - -
    - ---------------------------------------------------------------------

    THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
    PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS
    ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE
    WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
    IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE
    FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,
    CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF
    MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE
    POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
    OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES
    SO THE FOREGOING LIMITATION MAY NOT APPLY.

    -----BEGIN PGP SIGNATURE-----
    Version: PGP 7.1

    iQEVAwUBO9RPa40ZSRQxA/UrAQFT0Qf/cLyEfyJL/wFRiknDPflLhlWPOaaRlYLw
    m0vZK8i0Ldl9gKs0VmMaQXQgYiDlzTzuPZ7YRlrS3UVsjMobM/UpsI/X7slnFGIf
    fgach+VUqwSbNZcm/Y8FuER0dxJ1sqwjjrYmaVodTD7pUGv5/4ovAhephos3Vz20
    8See6sl5aqsdC2j1kGgpeleB9cR5sno17PfaiiacG2EDt4urRMhYSGn8rhzDH5kt
    365A4N+LFDt0pyIvKsfk4q91UT6kO7YwfvBpjhqBkqs5mjJd9pw/YzL1kIBM7MjO
    fk+KV8mVTT3PoJf4yz385KwXt3wpcxuk592fQk8bHRs9bPvKVjfJaw==
    =HyTQ
    -----END PGP SIGNATURE-----

       *******************************************************************
    You have received this e-mail bulletin as a result of your registration
    to the Microsoft Product Security Notification Service. You may
    unsubscribe from this e-mail notification service at any time by sending
    an e-mail to MICROSOFT_SECURITY-SIGNOFF-REQUESTANNOUNCE.MICROSOFT.COM
    The subject line and message body are not used in processing the request,
    and can be anything you like.

    To verify the digital signature on this bulletin, please download our PGP
    key at http://www.microsoft.com/technet/security/notify.asp.

    For more information on the Microsoft Security Notification Service
    please visit http://www.microsoft.com/technet/security/notify.asp. For
    security-related information about Microsoft products, please visit the
    Microsoft Security Advisor web site at http://www.microsoft.com/security.