Re: MS06-040: Vulnerability in Server service could allow remote code execution.



The patch is needed on any Windows 2000.

I am not sure why KB 921883
http://support.microsoft.com/?kbid=921883
it states as it does for applies to information, but I think I may, in that
the SBS issue was noted specifically in a revision after the initial doc
release, and this may have been with the Windows 2000 Sp4 mention
became trimmed to SBS




"Neil Jackson" <neil@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:WsWdncs-TemkHELZnZ2dnUVZ8tGdnZ2d@xxxxxxxxxxxx
Hi,

I haven't posted to a newsgroup for a long long time, I've searched high
and
low and cannot see an answer to this one but sorry if this has already
been
asked before.

MS06-040: Vulnerability in Server service could allow remote code
execution.

We have about 100 Windows 2000 Servers running Service Pack 4 for various
roles and about 1600 Windows 2000 Professional desktops. MS06-040 concerns
me and we have been advised by our peers to patch immediately to prevent
something terrible happening.

On the Technet at
http://www.microsoft.com/technet/security/bulletin/MS06-040.mspx it says:

Affected Software:

. Microsoft Windows 2000 Service Pack 4
. Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service
Pack
2
. Microsoft Windows XP Professional x64 Edition
. Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service
Pack 1
. Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft
Windows Server 2003 with SP1 for Itanium-based Systems
. Microsoft Windows Server 2003 x64 Edition

However on the Microsoft Knowledgebase article at
http://support.microsoft.com/?kbid=921883 , there is no specific mention
of
Windows 2000 and all we have mentioned is:

APPLIES TO:
Microsoft Windows 2000 Service Pack 4, when used with:
Microsoft Small Business Server 2000 Standard Edition

We don't use Small Business Server 2000 so my question is, does MS06-040
apply to my Windows 2000 Servers and my Windows 2000 Professional
Desktops,
all running SP4.

Secondly, if it does apply to Windows 2000 Server and Windows 2000
Professional, why arn't they mentioned on the knowledge base article?

Thanks in advance for clearing this up.

Cheers,

Neil.
System Support Engineer.





.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #177
    ... RobotFTP Server Username Buffer Overflow Vulnerability ... Ipswitch IMail Server Remote LDAP Daemon Buffer Overflow Vul... ... Microsoft Windows XP Help And Support Center Interface Spoof... ...
    (Focus-Microsoft)
  • Re: Printer Spooler Service Internet Access
    ... Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ... Print Spooler Vulnerability - CAN-2005-1984 ...
    (microsoft.public.windowsxp.help_and_support)
  • SecurityFocus Microsoft Newsletter #158
    ... Gamespy 3d IRC Client Remote Buffer Overflow Vulnerability ... Microsoft Windows PostThreadMessage() Arbitrary Process Kill... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #124
    ... Bladeenc Signed Integer Memory Corruption Vulnerability ... Opera JavaScript Console Attribute Injection Vulnerability ... Microsoft Windows 2000 NetBIOS Continuation Packets Kernel... ...
    (Focus-Microsoft)
  • Re: Error 80070005
    ... After you upgrade to Microsoft Internet Explorer 6.0 Service Pack 2 in ... Microsoft Windows XP SP2, some SSL-secured Web pages and Web sites may not ... this behavior is caused by security changes in Windows XP ... Update registry keys. ...
    (microsoft.public.windowsupdate)