Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > KB824146 (MS03-039) and KB823980 (MS03-026) on Server 2003 SP1

Reply
Thread Tools Display Modes

KB824146 (MS03-039) and KB823980 (MS03-026) on Server 2003 SP1

 
 
RSmith
Guest
Posts: n/a

 
      05-04-2005
Thorough scanning of our Server 2003 Service Pack 1 box has resulted in the
discovery of possible vulnerabilities related to the RPC DCOM systems within
Windows. Two test were used to check for RPC DCOM vulnerabilities: The first
test involved using ISS Internet Scanner with a policy to check for the
WinRpcssDcomBo vulnerability. The second test involved the use of Microsoft's
"KB824146scan" tool to check for missing patches KB824146 (MS03-039) and
KB823980 (MS03-026). These test were performed against a pre-SP1 Server 2003
box and resulted in negatives from both ISS (No vulnerabilities found) and
KB824146Scan ("X.X.X.X: patched with both KB824146 (MS03-039) and KB823980
(MS03-026)). The same test preformed against the same box with SP1 installed
netted different results. ISS came back with the WinRpcssDcomBo vulnerability
and KB824146Scan came back with "X.X.X.X: this host needs further
investigation". No configuration changes outside of the Service Pack install
were made to the Server 2003 box after installation (the firewall was left
off, etc.).

I've concluded that either:
A) The Server 2003 SP1 box is know vulnerable to RPC DCOM exploits as
covered in MS03-039, etc.
B) The Server 2003 SP1 box is responding to RPC DCOM queries in a way that
is making both ISS and KB824146Scan think it's vulnerable/missing patches.

Any other thought's/suggestions/ideas/conclusions would be greatly
appreciated. Of course I have lots of data (Windump, Netmon) that can be
looked at. {8^)


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MS03-26 Katya Windows Update 1 02-10-2004 12:53 AM
Patch Problems (MS03-042 and MS03-043) Mike T Windows Update 6 10-23-2003 12:02 PM
MS Security Bulletin MS03-39 (KB824146) fails to install Dietrich Schloegl Windows Update 3 10-01-2003 08:49 PM
MS03-031 Sql Julie D Windows Update 1 09-11-2003 08:29 PM
MS03-026 Lisa Windows Update 2 08-19-2003 01:40 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59