Vulnerability In Microsoft's Server Message Block for Windows XP and Windows 2000

A new vulnerability exists in Microsoft Server Message Block (SMB) that can permit an attacker to silently downgrade the SMB Signing settings on a vulnerable system.

Ken Pfeil

December 15, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported December 11, 2002, byMicrosoft.

VERSIONS AFFECTED

 

·        Microsoft Windows XP (prior to Service Pack 1--SP1)

·        Microsoft Windows 2000

 

 

DESCRIPTION

 

A new vulnerability exists in MicrosoftServer Message Block (SMB) that can permit an attacker to silentlydowngrade the SMB Signing settings on a vulnerable system. This vulnerabilitycan expose any SMB session to tampering, but the most serious scenario involveschanging Group Policy information as it's disseminated from a Win2K domaincontroller (DC) to a newly logged-on network client.

 

VENDOR RESPONSE

 

Microsofthas released Security Bulletin MS02-070,"Flaw in SMB Signing Could Enable Group Policy to be Modified(309376)," to address this vulnerability and recommends that affected usersimmediately apply the appropriate patch mentioned in the bulletin. This patch isincluded in XP SP1 and will be included in Win2K SP4.

 

CREDIT          

Discoveredby Microsoft.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like