The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin (MS01-007)
Time: 02:20 EST/07:20 GMT | News Source: Microsoft TechNet Security | Posted By: Will1

Microsoft has released a patch that eliminates a security vulnerability in Microsoft® Windows® 2000. The vulnerability could, under certain conditions, allow an attacker to gain complete control over an affected machine.

Network Dynamic Data Exchange (DDE) is a technology that enables applications on different Windows computers to dynamically share data. This sharing is effected via communications channels called trusted shares, which are managed by a service called the Network DDE Agent. By design, processes on the local machine can levy requests upon the Network DDE Agent, including ones that indicate what application should be run in conjunction with a particular trusted share. However, a vulnerability exists because, in Windows 2000, the Network DDE Agent runs using the Local System security context and processes all requests using this context, rather than that of the user. This would give an attacker an opportunity to cause the Network DDE Agent to run code of her choice in Local System context, as a means of gaining complete control over the local machine. In order to exploit this vulnerability, the attacker would need the ability to run a program on an affected machine that would levy the appropriate requests. However, best practices strongly recommend against ever allowing unprivileged users to run code on security-critical machines such as domain controllers and other servers; if these recommendations have been followed, such machines would not be at risk. In addition, terminal servers are not affected by this vulnerability (except in the case where unprivileged users are allowed to log on at the console, which is never recommended). As a result, workstations are likely to be the machines primarily affected by the vulnerability. This would tend to limit the damage that could be done via this vulnerability because, in most cases, even gaining complete control of a workstation would not convey any additional privileges on the domain. Microsoft recommends that customers using Windows 2000 workstations or who allow unprivileged users to run code on Windows 2000 servers apply the patch immediately. In addition, customers operating Windows 2000 web servers should consider applying the patch to those machines as well, as a precautionary measure. If an attacker were able to gain the ability to run code in a restricted context on a web server via another vulnerability, this vulnerability would provide a way to immediately elevate her privileges and cause broader damage.

Affected Software Versions

  • Microsoft Windows 2000 Professional
  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server

Patch Availability

You can also check out past Bulletins in our Microsoft Security Bulletin Summary List

Write Comment
Return to News

  Displaying 576 through 583 of 583
Prev | First
  The time now is 12:19:56 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/20/2025 2:24:18 PM
https://justpaste.me/ckdO
https://justpaste.me/cYbY1
https://justpaste.me/ZBWE2
https://justpaste.me/dDJg3
https://justpaste.me/dN761
https://justpaste.me/bE0P2
https://justpaste.me/d9lU3
https://justpaste.me/ZisR3
https://justpaste.me/bNga1
https://justpaste.me/Z7Kr2

#577 By 4240821 (82.115.4.230) at 7/22/2025 12:20:38 AM
https://www.pillowfort.social/posts/6432575
https://www.pillowfort.social/posts/6448755
https://www.pillowfort.social/posts/6451934
https://www.pillowfort.social/posts/6455348
https://www.pillowfort.social/posts/6449870
https://www.pillowfort.social/posts/6461285
https://www.pillowfort.social/posts/6446337
https://www.pillowfort.social/posts/6455598
https://www.pillowfort.social/posts/6437784
https://www.pillowfort.social/posts/6432977

#578 By 4240821 (82.115.4.230) at 7/23/2025 11:24:54 PM
https://moanio.com/video.php?id=2068
https://moanio.com/video.php?id=1877
https://moanio.com/video.php?id=5290
https://moanio.com/video.php?id=2565
https://moanio.com/video.php?id=2660
https://moanio.com/video.php?id=1036
https://moanio.com/video.php?id=741
https://moanio.com/video.php?id=5129
https://moanio.com/video.php?id=950
https://moanio.com/video.php?id=4287

#579 By 4240821 (82.115.4.230) at 7/24/2025 6:58:35 PM
https://moanio.com/video.php?id=1442
https://moanio.com/video.php?id=5153
https://moanio.com/video.php?id=4663
https://moanio.com/video.php?id=2793
https://moanio.com/video.php?id=3110
https://moanio.com/video.php?id=5749
https://moanio.com/video.php?id=4863
https://moanio.com/video.php?id=5385
https://moanio.com/video.php?id=294
https://moanio.com/video.php?id=974

#580 By 4240821 (82.115.4.230) at 7/26/2025 6:45:40 PM
https://moanio.com/video.php?id=4993
https://moanio.com/video.php?id=3025
https://moanio.com/video.php?id=560
https://moanio.com/video.php?id=2037
https://moanio.com/video.php?id=4611
https://moanio.com/video.php?id=850
https://moanio.com/video.php?id=3590
https://moanio.com/video.php?id=183
https://moanio.com/video.php?id=2551
https://moanio.com/video.php?id=3881

#581 By 4240821 (82.115.4.230) at 7/28/2025 11:40:08 PM
https://moanio.com/video.php?id=1469
https://moanio.com/video.php?id=3690
https://moanio.com/video.php?id=1885
https://moanio.com/video.php?id=4635
https://moanio.com/video.php?id=1490
https://moanio.com/video.php?id=4524
https://moanio.com/video.php?id=1263
https://moanio.com/video.php?id=1786
https://moanio.com/video.php?id=5846
https://moanio.com/video.php?id=722

#582 By 4240821 (82.115.4.230) at 7/29/2025 5:39:22 PM
https://justpaste.me/ZUsY2
https://justpaste.me/bf0e2
https://justpaste.me/eUuv2
https://justpaste.me/dXVJ1
https://justpaste.me/bh2H2
https://justpaste.me/c6SP1
https://justpaste.me/g0zE1
https://justpaste.me/ZjC62
https://justpaste.me/aLgr1
https://justpaste.me/fqPG

#583 By 4240821 (82.115.4.230) at 7/30/2025 9:24:11 AM
https://justpaste.me/dCmL1
https://justpaste.me/ZAiA1
https://justpaste.me/e6lY4
https://justpaste.me/bqqw2
https://justpaste.me/fwYx3
https://justpaste.me/bs8X4
https://justpaste.me/euLI8
https://justpaste.me/aAW04
https://justpaste.me/bE0P2
https://justpaste.me/ZsBW1

Write Comment
Return to News
  Displaying 576 through 583 of 583
Prev | First
  The time now is 12:19:56 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *