ITS Homepage Click here for text version of ITS homepage University at AlbanyUAlbany Site IndexUAlbany Search
alerts_tag

ITS Alerts
Proof of Concept Code released for several Vulnerabilities detailed in October Microsoft


 

ALARM Group ALERT ¿ click for a description of ALARM, The Computing Alert System
Alert Number:  101405-01
Alert Date:  10/14/05
Alert Title:    Proof of Concept Code released for several Vulnerabilities detailed in October Microsoft security bulletin

Update-to: 
101305-01 "Exploit released for Vulnerability detailed in October Microsoft security bulletin"
101205-01 "TCP port 3372 blocked in response to Microsoft DTC and COM+ exploit"
101105-01 "Microsoft releases security bulletin for October"

OS/Platform/Application:
Windows Server 2003 (including Service Pack 1, x64 Edition, and SP1 for Itanium-based Systems )
Windows XP (Service Packs 1 and 2, also *CRITICAL* XP Professional x64 Edition *CRITICAL*)
Windows 2000 Service Pack 4

Category:  UPDATE
Severity:  HIGH
Attention: 
Windows System Administrators, Desktop Support Personnel

Summary:  Proof of Concept Code has been published for three vulnerabilities addressed in the October Microsoft Security Bulletin.  Proof of Concept code often serves as the basis for exploits that circulate the Internet; the release of such code is therefore considered to be a precursor to new attacks.  The most recently released code addresses bulletins MS05-044, MS05-045, and MS05-048.  Microsoft rates these bulletins in a range between "low" and "important", with the exception of MS05-048 which is deemed as "Critical" for Systems using Windows XP Professional x64 Edition.

Recommended Actions:  Windows system managers and support personnel are strongly encouraged to read these bulletin (including all potential caveats) and (if appropriate) apply these patches AS SOON AS POSSIBLE as per the instructions provided by the vendor if they have not already done so.

ITS Actions:  ITS Systems Management and Operations Staff will apply the patches to the propriate ITS servers as part of the next scheduled system update.

Resources:
Security Bulletin Summary for August 2005:
http://www.microsoft.com/technet/security/bulletin/ms05-oct.mspx

Security Bulletin MS05-044 Vulnerability in the Windows FTP Client
Could Allow File Transfer Location Tampering
http://www.microsoft.com/technet/security/bulletin/MS05-044.mspx

Security Bulletin MS05-045 Vulnerability in Network Connection
Manager Could Allow Denial of Service
http://www.microsoft.com/technet/security/bulletin/MS05-045.mspx

Security Bulletin MS05-048  Vulnerability in the Microsoft
Collaboration Data Objects Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/bulletin/MS05-048.mspx

 

 

BLANKABCDEFGHIJKLMBLANK
BLANKNOPQRSTUVWXYZBLANK
CHOOSE FROM the ITS Site Index

GO TO an ITS Group
Information Technology Services
University at Albany, SUNY
1400 Washington Avenue
Albany, NY 12222
ITS Service Centers:  518-442-4000
 
University at Albany Home Page
Contact UAlbany | Directories | Calendars | Visitors | Site Index | Search
Admissions | Academics | Research | IT Services | Libraries | Athletics

Internet Privacy Policy              IT Policies