R E L A T E D   C O N T E N T
ADVERTISEMENT

Microsoft fixes eight-month old flaw

Critical vulnerability could give hackers 'complete control'

Steve Ranger, vnunet.com 11 Feb 2004
ADVERTISEMENT

Microsoft is warning of yet another critical flaw which could give hackers "complete control" over computers running one of several versions of its operating system.

The software giant confirmed that the flaw affects Microsoft Windows NT 4.0, NT Server 4.0 Terminal Server Edition, Windows 2000, XP and Server 2003. Systems administrators should apply the update immediately, Microsoft said.

The security vulnerability exists in the Microsoft Abstract Syntax Notation 1 (ASN.1) Library, deep within the system code.

Microsoft said an attacker using a buffer overflow to exploit the vulnerability could execute code with system privileges on an affected system.

"The attacker could then take any action on the system, including installing programs, viewing data, changing data, deleting data, or creating new accounts with full privileges," the company warned.

But Microsoft said in the most likely exploitable scenario, an attacker would have to have direct access to the user's network.

Server systems are at greater risk than client computers because they are more likely to have a server process running that decodes ASN.1 data.

ASN.1 is a data standard used by many applications to allow the understanding of data across various platforms.

Although Microsoft has known about the flaw since last July, it claims that the breadth of systems affected has caused the long delay before a one-patch-fixes-all release could be issued.

Microsoft has come under fire for weaknesses in its software. Only last week it issued an emergency fix for Internet Explorer, fixing a flaw exploited by hackers to imitate websites in so-called 'phishing' attacks for users' personal details.

Click here for full details of the patch update.

See also:

With more computer viruses reported every day, it may seem like we're fighting a losing battle but there are plenty of simple ways to keep your PC safe from harm. Let us show you how.  29 Oct 2003

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | MHRA
Senior Technical Analyst - £26,781 - £28,562 - London The Medicines and Healthcare products Regulatory Agency (MHRA) is the government agency which is responsible for ensuring that medicines and medical devices work, and are acceptably ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
London, United Kingdom | The Crown Estate
 EDM Administrator - London - £22,300 to £24,200pa The Crown Estate is a unique organisation that manages a vast and varied property portfolio, comprising commercial, agricultural and marine interests throughout Britain. We are looking for an ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 396477 Environment Support Engineer Location - Reading Job Description: There is an initial requirement an Environment Support Engineer to provide support and maintenance for the development environments within ATLAS. This role encompases many ... more >
More job opportunities