
Let's go to work...
By Robert Lemos
Published: 14 January 2004 10:05 GMT
Microsoft has released patches for three flaws, the most serious of which could give attackers a back door into the company's security server product.
The most major flaw affects Microsoft's Internet Security and Acceleration Server 2000, which is included with Small Business Server 2000 and 2003 editions. The flaw lies in the way a filter in the server product's firewall processes data formatted in the real-time multimedia communications standard, known as International Telecommunications Union (ITU) H.323.
Internet Security and Acceleration Server is designed to help protect companies' networks from online attacks.
Stephen Toulouse, security program manager at Microsoft, said: "It is kind of the same situation that we have seen - a certain level of human error is going to be present, and that is true even for security software."
The H.323 flaw was found by the National Infrastructure Security Co-ordination Centre, the UK's internet infrastructure protection agency, and researchers from the University of Oulu, in Finland.
Many companies, primarily makers of voice over Internet Protocol equipment, also likely are affected by the issue - but to a lesser extent than Microsoft's product.
The other flaws the software giant announced include a vulnerability in the Microsoft Data Access Component software in Windows 2000 and XP, along with Microsoft's SQL Server 2000 and Windows Server 2003. The flaw could allow an attacker to take over a vulnerable system - only after successfully disguising the attacking computer as an SQL server. Because of the complexity of the attack, Microsoft graded the flaw as "important," not critical.
The last vulnerability, in Exchange Server 2003, allows an attacker to abuse the Online Web Access module to access the email inbox of another random user who recently accessed the server.
"The end result is that an attacker could, under certain circumstances, get access to a complete random user," Microsoft's Toulouse said.
Microsoft posted discussions and patches for the products on its website and will automatically provide fixes to its customers through its update service.
Along with the three vulnerabilities, Microsoft re-released another patch that had caused computers that run Windows in Hebrew, Arabic and Thai to crash.
Robert Lemos writes for CNET News.com
C# Developer C#, ASP.NET, SQL Server, SharePoint - Abingdon, Oxfordshire, South East UK - REF:2103 Would you like to hone your C# / ASP.NET / SQL ...
London - C# Loans Developer - C#, SQL Server, Leveraged Loans I am currently hiring for a Hedge Fund who are looking a C# Winforms Developer with ...
One of the world's leading international investment banks is currently looking to hire a .Net developer with strong C# and strong knowledge of SQL ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...