Home
Resources
Training
About Us
eStore

>

resources > bulletins > MS06-063

 

 

 

 

 

 

 

Latest Blog: Log monitoring and the Terry Childs/City of San Francisco debacle

 

Microsoft Security Bulletin MS06-063 - Vulnerability in Server Service Could Allow Denial of Service (923414)

This one is more than a denial of service issue.  This bulletin addresses 2 vulnerabilities in the Server service – only one of them being simple denial of service.  The other (SMB Rename Vulnerability) as clarified in the FAQ is a full blown remote code execution allowing an attacker with valid logon credentials to take over a remote computer via UDP ports 135, 137, 138 and 445, and TCP ports 135, 139, 445 and 593.  Due to the prevalence of Internet firewalls and the fact that logon credentials are required this vulnerability becomes primarily an insider issue. Exploit details and proof of concept code are public but no reports of attacks as of yet.  I suggest immediately initiating testing of this patch followed by deployment to all servers.  Workstations with properly configured firewalls are less likely to be affected by this vulnerability.

Get this valuable commentary each month as soon as Microsoft releases security updates!

Free log parser scripts, a clear explanation of Microsoft's latest security bulletin, helpful security tips, how-to's and more.

Email address:

 

Newsletter archive
Your e-mail address will be held strictly confidential and you can unsubscribe at any time.


Upcoming Webinars by Randy Franklin Smith


Additional Links

A
D
V