SEcurity patch message

From: Bill G. (anonymous_at_discussions.microsoft.com)
Date: 10/28/03


Date: Tue, 28 Oct 2003 11:35:02 -0800


 This is what came to me by means of a pop-up. Is this
the bs I think it is. This page is from
www.connectsecurely.com.
Thanks for the heads-up.

 Microsoft Home | MSN Home | Subscribe | Manage
Your Profile
Microsoft Security Bulletin MS03-043

 

Buffer Overrun in Messenger Service Could Allow Code
Execution (828035)
Issued: October 22, 2003
Version Number: 1.1

Summary
Who Should Read This Document: Customers using Microsoft®
Windows®

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should install the patch
immediately

Caveats: None

Tested Software and Patch Download Locations:

Affected Software:

Microsoft Windows NT Workstation - Download the patch
Microsoft Windows NT - Download the patch
Microsoft Windows 2000 - Download the patch
Microsoft Windows XP - Download the patch
Microsoft Windows Win98 -Download the patch
Microsoft Windows Server 2003 - Download the patch
Non Affected Software:

Microsoft Windows Millennium Edition
The software listed above has been tested to determine if
the versions are affected. Other versions are no longer
supported, and may or may not be affected.

Technical Description:

A security vulnerability exists in the Messenger Service
that could allow arbitrary code execution on an affected
system. The vulnerability results because the Messenger
Service does not properly validate the length of a
message before passing it to the allocated buffer.

An attacker who successfully exploited this vulnerability
could be able to run code with Local System privileges on
an affected system, or could cause the Messenger Service
to fail. The attacker could then take any action on the
system, including installing programs, viewing, changing
or deleting data, or creating new accounts with full
privileges.

Mitigating factors:

Messages are delivered to the Messenger service via
NetBIOS or RPC. If users have blocked the NetBIOS ports
(ports 137-139) - and UDP broadcast packets using a
firewall, others will not be able to send messages to
them on those ports. Most firewalls, including Internet
Connection Firewall in Windows XP, block NetBIOS by
default.
Disabling the Messenger Service will prevent the
possibility of attack.
On Windows Server 2003 systems, the Messenger Service is
disabled by default.
Severity Rating:

 

Windows NT Critical
Windows Server NT 4.0 Terminal Server Edition Critical
Windows 2000 Critical
Windows XP Critical
Windows Server 2003 Moderate

 

The above assessment is based on the types of systems
affected by the vulnerability, their typical deployment
patterns, and the effect that exploiting the
vulnerability would have on them.

 
 



Relevant Pages

  • help
    ... being asked to send $19.95 to receive this patch? ... Buffer Overrun in Messenger Service Could Allow Code ... Tested Software and Patch Download Locations: ... Microsoft Windows NT - Download a fix to patch this issue ...
    (microsoft.public.windowsxp.general)
  • Re: !!Windows Is Infected!!
    ... trying to sell you patches that Microsoft provides free-of-charge. ... Messenger Service of Windows ... belive its a fake microsoft site the patch links on the ... Microsoft Windows NT Workstation ...
    (microsoft.public.windowsxp.general)
  • Re: Windows XP Patch Release Oct 24th
    ... You need to download the 32 bit version. ... been releases since Service Patch 1. ... They are in addition to Service Pack 1. ... > Microsoft Windows XP 64-bit Edition: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Microsoft Security Bulletin MS02-071 Update
    ... I installed the previous patch on a couple of WinNT 4.0 servers. ... Microsoft Windows NT 4.0; ... The bulletin has been updated to include the new download ... > The Microsoft Security Response Center has released Microsoft Security ...
    (microsoft.public.security)
  • Re: Microsoft Security Bulletin MS02-055
    ... The MS02-055 security patch appears to be affecting my server adversely - ... This is one server out of three that are load-balanced. ... > Microsoft Windows 98 Second Edition ...
    (microsoft.public.security)