Information Technology Services: Alerts Archive

ALARM Group ALERTclick for a description of ALARM, The Computing Alert System
Alert Number:  082605-01
Alert Date:  08/26/05
Alert Title:  Microsoft Security Advisory addresses vulnerability in XP SP1
Update-to:  080905-01 'Microsoft releases security bulletin for August'
OS/Platform/Application:  Microsoft Windows XP Service Pack 1
Category:  ALERT
Severity:  LOW
Attention:  System Administrators, Desktop Support Personnel

Summary:  Microsoft has recently released security advisory 906574. This advisory addresses a vulnerability in certain nonstandard configurations of Windows XP Service Pack 1. The vulnerability was originally detailed in Security Bulletin MS05-039 (Released on August 9) and has been the basis for the recent outbreak of the Zotob worm and associated variants. Prior to the release of advisory 906574 only Windows 2000 systems were thought to be actively exploitable via this vulnerability. At the time of this writing no known exploit for this vulnerability (Specific to XP SP1 platforms) has been observed/reported to be circulating in the wild.

Recommended Actions:  As a preventive measure, System Administrators and Desktop Support Personnel who maintain Windows XP SP1 systems are encouraged to read the vendor's Security Advisory page (link provided below) and (if appropriate) apply the necessary updates at their earliest convenience.

ITS Actions:  ITS is taking no specific additional actions to address this vulnerability/product update. An update will be issued if this situation changes.

Resources:
Microsoft Security Advisory 906574
NetworkWorld Article on XP vulnerability

University at Albany homepage