Vulnerability In Microsoft's Server Message Block for Windows XP and Windows 2000
A new vulnerability exists in Microsoft Server Message Block (SMB) that can permit an attacker to silently downgrade the SMB Signing settings on a vulnerable system.
December 15, 2002
Reported December 11, 2002, byMicrosoft.
VERSIONS AFFECTED
· Microsoft Windows XP (prior to Service Pack 1--SP1)
· Microsoft Windows 2000
DESCRIPTION
A new vulnerability exists in MicrosoftServer Message Block (SMB) that can permit an attacker to silentlydowngrade the SMB Signing settings on a vulnerable system. This vulnerabilitycan expose any SMB session to tampering, but the most serious scenario involveschanging Group Policy information as it's disseminated from a Win2K domaincontroller (DC) to a newly logged-on network client.
VENDOR RESPONSE
Microsofthas released Security Bulletin MS02-070,"Flaw in SMB Signing Could Enable Group Policy to be Modified(309376)," to address this vulnerability and recommends that affected usersimmediately apply the appropriate patch mentioned in the bulletin. This patch isincluded in XP SP1 and will be included in Win2K SP4.
CREDIT
Discoveredby Microsoft.
Read more about:
MicrosoftAbout the Author
You May Also Like