A Digital Age Deserves A Digital Leader

SECURITY UPDATE - ASN.1 Vulnerability [MS04-007]

SECURITY UPDATE - ASN.1 Vulnerability [MS04-007]

Postby ODiaz86 » Thu Feb 12, 2004 2:44 pm

SECURITY UPDATE
ASN.1 Vulnerability Could Allow Code Execution
11 February 2004
Severity Rating: Critical

Risk Impact:
Remote code execution

Affected Software:
Microsoft Windows XP (XP, XP 64-bit edition and XP 64-bit edition 2003), Windows 2000, Windows NT (Workstation 4.0, Server 4.0 and Server 4.0 Terminal Server Edition) and Windows Server 2003 (2003 and 64-bit edition).

Details:
This vulnerability is caused by unchecked buffer in Microsoft ASN.1 Library which results in buffer overflow. An attacker which exploit this vulnerability could execute code with system privileges on an affected system. The attacker can take any action on the system, including installing programs, viewing data, changing data, deleting data and creating new accounts with full privileges. This vulnerability could also be exploited by an internet worm, including the recent Blast worm (also known as MSBlast).

Patch Availability:

http://www.microsoft.com/technet/

Please visit this page and select the correct version of Windows for the security patch.
Please visit the source for details of patches.

:source: Microsoft Security Bulletin MS04-007, Sophos and eEye Digital Security.
Image
Image
PRO Level 12
User avatar
Posts: 510
Joined: Wed Jun 26, 2002 3:33 pm
Location: Millville, New Jersey - USA
Real Name: Omar Diaz

Postby MinusDriver » Thu Feb 12, 2004 5:57 pm

You can also go here for more info: Click Here
PRO Level 13
User avatar
Posts: 813
Joined: Thu Jan 08, 2004 9:47 pm
Location: Atlanta, GA
Real Name: Michael

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 3 guests

cron
cron