Patch Issued for W2K Domain Controller Memory Leak
A loophole in the Windows 2000 will allow both internal and external attacks to take lower domain controller, according to a Microsoft security bulletin sent late Tuesday.
Sweden, the so-called Internet security company defcom reported problems, Microsoft and help solve the problem.
"Core services running on a Windows 2000 domain controller contains a memory leak, it can be triggered when it attempted to process a certain type of invalid service requests," Microsoft Notice the full text of the security. Because it is a core service for the domain controller, it can not be closed, in order to prevent this problem.
Should take advantage of this vulnerability, the attacker will be issued them invalid request repeatedly consumption of available memory on the server. The attack could domain controller and insensitive handling Sign issued a new request or Kerberos tickets.
Boot patch, Microsoft, the company said it also maintained a normal safety practices, such as the deployment of a firewall to prevent outside users sent at the request of the domain controller. However, the vulnerability can also be used from the enterprise network.
The bug affects Windows 2000 Server, Windows 2000 Advanced Server and Windows 2000 servers in the data center running as a domain controller computer, but does not affect Windows NT 4.0 server.
Fixes Microsoft plans to launch with Windows 2000 Service Pack 3.
Microsofts security bulletin, on the 24th this year, can be found here. -- Other recent Safety News: sadmind / illegal immigrants worms unpatched system anti-virus companies released the list of popular virus in April illegal immigrants on the 5th vulnerabilities could allow the non - authorized control w2k Microsoft confirmed the vulnerability in the ISA Server 2000
Check Point Exams Available Through VUE (Checkpoint)
No Windows 2000 SP5, Expect Security Rollup Instead (Microsoft)
Google Upgrades Corporate Search Engine (BEA)
Stolen Yale Computers Contained 10,000 SSNs (TIA)
Microsoft Debuts Windows CE Beta (Microsoft)
Licensing the Virtual Future (Microsoft)
UPDATED (Microsoft)
Vertical Markets (Microsoft)
Cisco Raises CCIE Exam Fees (Cisco)
Cisco To Update Security, Service Labs (Cisco)
Managed Security Services Poised for Steady Growth (Cisco)
New Office, Vista To Feature Improved Disability Access (Microsoft)
MuleSource Kicks Into SOA Governance (ISC)
Proof of Life (Oracle)
Bebo To Add IM Powered by Microsoft (Microsoft)
Computer Associates Ships SMB Protection Suites (Computer Associates)
WSJ Reporter Told HP Leak Probe Details (HP)
A Guide to PCs This Holiday Season (HP)
A Milestone in the Higher Ed Software Market? (Oracle)
Watch It (Microsoft)