PDA

View Full Version : Here We Go Again: Microsoft Issues New Security Fix



Joshua
09-11-2003, 10:29 AM
I am posting this here since it looks to be just as bad as the Blaster/Welchia exploit.. EVERYONE, RUN WINDOWS UPDATE NOW!!

-------------------------------------------------


by Paul Thurrott, [email protected]

Here We Go Again: Microsoft Issues New Security Fix
In July, Microsoft released a critical security fix, warning users
that attackers could use the specified vulnerability to take over
users' systems and wreak havoc on the Internet. A month later the
infamous MSBlaster worm exploited that vulnerability. Yesterday,
Microsoft released another critical security fix that fixes a
vulnerability that's painfully similar to the one that led to
MSBlaster. If you didn't feel sufficiently warned the first time
around, take this warning to heart: You need to install this fix
immediately.
The fix, one of three detailed in Microsoft Security Bulletin
MS03-039 (Buffer Overrun In RPCSS Service Could Allow Code Execution),
supersedes and includes the fix for the earlier vulnerability,
detailed in Microsoft Security Bulletin MS03-026(Buffer Overrun In RPC
Interface Could Allow Code Execution). As with the original
vulnerability, the new vulnerability that MS03-039 fixes involves the
remote procedure call (RPC) technology in various Windows NT-based
Windows versions, including Windows Server 2003, Windows XP, Windows
2000, NT Workstation 4.0, NT Server 4.0, and NT Server 4.0, Terminal
Server Edition (WTS).
If you have a recent Windows version, you can simply download the
patch from Windows Update or Auto Update, features that are included
with your OS. For more information about the security patch or the
other tools Microsoft offers to protect your system, visit the
Microsoft Web site.
http://www.microsoft.com/technet/security/bulletin/ms03-039.asp

topane
09-11-2003, 11:01 AM
Isn't this a repost? :hehehmm:

Joshua
09-11-2003, 11:08 AM
:D No.. A new one if you can believe it.

Jenny
09-11-2003, 11:25 AM
did it last night :)

nickel
09-11-2003, 11:40 AM
Originally posted by Jenny
did it last night :)
me 2 ;)

nickel
09-11-2003, 12:28 PM
Originally posted by chosenfool


so much for NOT catching a virus....


;) :P

aw.... too bad for you. go see your Doc asap. :P

eSDee
09-12-2003, 12:29 AM
You might want to make this a sticky ;)

bachviet
09-12-2003, 07:01 AM
All my computers are batched!

billxp
09-15-2003, 04:55 PM
Gibson Research has a nice little app that will turn of Dcom once and for all. Which is good if you don't need it.
Get it here http://grc.com/dcom/

Booyamos
09-20-2003, 03:34 PM
oh my god I want to break computers. This is such a pain for us at work. Stupid faculty and staff don't understand that leave your computer on at night means: LEAVE YOUR COMPUTER ON AT NIGHT. We push out the patches when they leave but half the danged professors turn everything off. Ugh. These security fixes and viruses are such a pain.

ArkiStan
10-10-2003, 08:11 AM
How can I check if I've already done this? I searched for available critical updates and got (0). Does that mean I've installed it?

Joshua
10-29-2003, 08:03 PM
Looks like we can take this down now.