Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Microsoft Security Advisory (922437): Exploit Code Published Affectingthe Server Service ( KB917537 )

Reply
Thread Tools Display Modes

Microsoft Security Advisory (922437): Exploit Code Published Affectingthe Server Service ( KB917537 )

 
 
MowGreen [MVP]
Guest
Posts: n/a

 
      08-12-2006
Microsoft Security Advisory (922437)
http://www.microsoft.com/technet/sec...ry/922437.mspx

> Microsoft is aware that detailed exploit code has been published on the
> Internet for the vulnerability that is addressed by Microsoft security
> bulletin MS06-040. Microsoft has verified the published exploit code to
> work on Windows 2000 and Windows XP Service Pack 1 only; this code does
> not affect Windows XP Service Pack 2, Windows Server 2003, or Windows
> Server 2003 Service Pack 1. At this time our investigation of this exploit
> code has verified that it does not affect customers who have installed the
> update detailed in MS06-040.


The Microsoft Security Response Center Blog reports :
http://blogs.technet.com/msrc/archiv...11/446078.aspx

> This morning we released Security Advisory 922437 because we're aware of
> exploit code that has been published on the Internet for the vulnerability
> that is addressed by Microsoft security bulletin MS06-040. We've verified
> that this exploit code can allow remote code to execute on Windows 2000
> and Windows XP Service Pack 1 only. In its current state, this code
> does not affect Windows XP Service Pack 2, Windows Server 2003, or Windows

Server
> 2003 Service Pack 1. Also, we've verified that this exploit code does not
> affect customers who have installed the MS06-040 update on their systems.



Direct download links to the update are in the MS06-040 Security
Bulletin under the " Tested Software and Security Update Download Locations
Affected Software: " heading -

http://www.microsoft.com/technet/sec.../MS06-040.mspx


MowGreen [MVP 2003-2006]
===============
*-343-* FDNY
Never Forgotten
===============


 
Reply With Quote
 
 
 
 
NewScience
Guest
Posts: n/a

 
      08-12-2006
I knew that this would 'bite' MS in the end someday. I've constantly 'sent
reports' to MS thru the years about their software NOT checking return codes
when allocating buffers in software.

I've sent reports over and over since Windows 95. Windows is fraught with
these problems throughout many of the DLLs, and as Windows' is getting
bigger, so are the problems ... and hackers know it.

I don;t understand where their heads are at when developing new software and
not verifying simple return codes and error checking.

"MowGreen [MVP]" <> wrote in message
news:...
> Microsoft Security Advisory (922437)
> http://www.microsoft.com/technet/sec...ry/922437.mspx
>
>> Microsoft is aware that detailed exploit code has been published on the
>> Internet for the vulnerability that is addressed by Microsoft security
>> bulletin MS06-040. Microsoft has verified the published exploit code to
>> work on Windows 2000 and Windows XP Service Pack 1 only; this code does
>> not affect Windows XP Service Pack 2, Windows Server 2003, or Windows
>> Server 2003 Service Pack 1. At this time our investigation of this
>> exploit code has verified that it does not affect customers who have
>> installed the update detailed in MS06-040.

>
> The Microsoft Security Response Center Blog reports :
> http://blogs.technet.com/msrc/archiv...11/446078.aspx
>
>> This morning we released Security Advisory 922437 because we're aware of
>> exploit code that has been published on the Internet for the
>> vulnerability that is addressed by Microsoft security bulletin MS06-040.
>> We've verified that this exploit code can allow remote code to execute on
>> Windows 2000 and Windows XP Service Pack 1 only. In its current state,
>> this code does not affect Windows XP Service Pack 2, Windows Server 2003,
>> or Windows

> Server
>> 2003 Service Pack 1. Also, we've verified that this exploit code does not
>> affect customers who have installed the MS06-040 update on their systems.

>
>
> Direct download links to the update are in the MS06-040 Security Bulletin
> under the " Tested Software and Security Update Download Locations
> Affected Software: " heading -
>
> http://www.microsoft.com/technet/sec.../MS06-040.mspx
>
>
> MowGreen [MVP 2003-2006]
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Security Advisory (943521) Donna Buenaventura \(MVP\) Windows Vista Security 38 10-16-2007 11:33 AM
Security Advisory MS06-040 Ken_Foster_ca Windows Vista Security 3 08-15-2006 08:46 PM
Security Update KB917537 continues to fail installation Rob Gordon Windows Update 1 07-17-2006 03:24 PM
Microsoft Security Advisory - 913333 released Jian Ming Windows Update 1 02-11-2006 03:26 PM
DSO Exploit Security Hole in IE Carolyn Windows Update 2 08-05-2004 06:51 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59