Information Technology Services: Alerts Archive

ALARM Group ALERTclick for a description of ALARM, The Computing Alert System
Alert Number:  020905-01
Alert Date:  02/09/05
Alert Title:  Microsoft re-releases one security bulletin for February
Update-to:  none
OS/Platform/Application: 
 Microsoft Windows XP (64-bit Edition Version 2003)
 Microsoft Windows Server 2003 (Including 64-bit Edition)
 Microsoft Exchange Server 2003 (including SP1 when installed on Microsoft
 Windows Server 2003 )
 Microsoft Exchange Server 2003 (when installed on Microsoft Windows 2000
 Service Pack 3 or Microsoft Windows 2000 Service Pack 4)
 Microsoft Exchange 2000 Server Service Pack 3
Category:  ALERT
Severity:  HIGH
Attention:  Windows System Administrators, Desktop Support Personnel

Summary:  In addition to the release of 12 new security bulletins On February 8, Microsoft released an update to a bulletin originally released on October 12, 2004 (Microsoft Security Bulletin MS04-035, Vulnerability in SMTP Could Allow Remote Code Execution <885881>). This update (listed as "critical" by the vendor) addresses a newly-discovered vulnerability in the SMTP component of the above-listed software. Exploitation of this vulnerability could allow an attacker to take complete control of a vulnerable system.

Recommended Actions:  Persons who manage or maintain any of the above-listed software are encouraged to read the bulletin (including the associated caveats) and (if appropriate) apply the patch(es) immediately as per the instructions detailed in the bulletin(s).

ITS Actions:  At this time, ITS is taking no specific additional actions to address this bulletin re-release.

Resources:
Microsoft Security Bulletin MS04-035:

University at Albany homepage