Alert: Microsoft Security Bulletin MS03-041 - Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)
From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 10/15/03
- Previous message: Russ: "The Ultimate Leading Edge International IT Conferences and Expos"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 15 Oct 2003 17:21:59 -0400 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Summary:
Version Number: V1.0
Revision Date: 10-15-2003
Patch(es) Replaced: None
Caveats: None
Tested Software and Patch(es) Locations (URLs are probably wrapped):
Affected Software:
* Microsoft Windows NT Workstation 4.0, Service Pack 6a
* Microsoft Windows NT Server 4.0, Service Pack 6a
* Microsoft Windows NT Server 4.0, Terminal Server Edition, Service
Pack 6
* Microsoft Windows 2000, Service Pack 2
* Microsoft Windows 2000, Service Pack 3, Service Pack 4
* Microsoft Windows XP Gold, Service Pack 1
* Microsoft Windows XP 64-bit Edition
* Microsoft Windows XP 64-bit Edition Version 2003
* Microsoft Windows Server 2003
* Microsoft Windows Server 2003 64-bit Edition
Software Not Affected:
* Microsoft Windows Millennium Edition
Technical Description:
There is a vulnerability in Authenticode that, under certain low memory
conditions, could allow an ActiveX control to download and install
without presenting the user with an approval dialog. To exploit this
vulnerability, an attacker could host a malicious Web Site designed to
exploit this vulnerability. If an attacker then persuaded a user to
visit that site an ActiveX control could be installed and executed on
the user's system. Alternatively, an attacker could create a specially
formed HTML e-mail and send it to the user. If the user viewed the HTML
e-mail an unauthorized ActiveX control could be installed and executed
on the user's system. In both scenarios the vulnerability in
Authenticode could allow an unauthorized ActiveX control to be installed
and executed on the user's system, with the same permissions as the
user, without prompting the user for approval. The risk of attack from
the HTML email vector can be significantly reduced if the following
conditions are met:
* You have applied the patch included with Microsoft Security bulletin
;
http://www.microsoft.com/technet/security/bulletin/MS03-040.asp
* You are using Internet Explorer 6 or later
* You are using the Microsoft Outlook Email Security Update or
Microsoft Outlook Express 6.0 and higher, or Microsoft Outlook 2000 or
higher in their default configuration.
This email is sent to NTBugtraq automatically as a service to my
subscribers. (v2.0)
Cheers,
Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor
---- NTBugtraq subscribers save $103.00 off the TICSA exam by using promo code "NT1003" when registering to take the TICSA exam at www.2test.com. Prove to your employer and peers that you have the knowledge and abilities to be an active stakeholder in today's enterprise security. Become TICSA certified www.trusecure.com/ticsa. Promotion expires 12/31/03 and cannot be used in combination with other offers. ----
- Previous message: Russ: "The Ultimate Leading Edge International IT Conferences and Expos"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|