PC Review


Reply
Thread Tools Rate Thread

ASN flaw just a single anomaly says Microsoft

 
 
Daeron
Guest
Posts: n/a
 
      11th Feb 2004
Microsoft ASN flaw may be biggest defect ever found
Shawna McAlearney Feb 10 2004

Enterprises are scrambling to patch their systems in the wake of
Microsoft Corp.'s vulnerability blitz Tuesday that revealed a critical
flaw affecting multiple Windows operating systems. The vulnerability
can permit an unauthenticated, remote attacker to execute arbitrary
code with system privileges.

[..]

"It's the biggest Microsoft flaw we've found -- maybe the biggest ever
found," said Marc Maiffret, chief hacking officer at Aliso Viejo,
Calif.-based eEye Digital Security, which discovered the flaw.

"Because it's in a shared component, it has multiple avenues for
attacks -- everything from file sharing to IPSec."

According to Maiffret, the ASN.1 flaw was reported to Microsoft 200
days before the patch was released.

".. This was an instance in which due diligence required us to very
carefully evaluate the broadest possible implications of a single
anomaly reported to us." [Microsoft spokesperson]

In this instance, integer overflows and other flaws in integer
arithmetic cause a vulnerability in the ASN.1 parser library in
Microsoft Windows NT 4.0, 4.0 TSE, 2000, XP and Server 2003. According
to the Computer Emergency Response Team (CERT), any application that
loads the ASN.1 library could serve as an attack vector.
http://searchwin2000.techtarget.com/...950106,00.html
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
FYI - Microsoft Acknowledges XL Flaw RagDyer Microsoft Excel Discussion 13 18th Jan 2008 02:29 PM
FYI - Microsoft Acknowledges XL Flaw RagDyer Microsoft Excel Misc 13 18th Jan 2008 02:29 PM
FYI - Microsoft Acknowledges XL Flaw RagDyer Microsoft Excel Worksheet Functions 8 18th Jan 2008 02:29 PM
Microsoft Windows | MSN Flaw Windows Microsoft C# .NET 4 27th Jul 2007 06:29 PM
Microsoft: SP2 shimmy's not a flaw anonymous Windows XP General 0 2nd Feb 2005 04:56 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:14 AM.