On October 18, 2001 Microsoft released the original version of this bulletin. On October 19, 2001, an issue was identified with the Windows 2000 patch. The patch was withdrawn so that it could be updated and re-released. On October 22, 2001 the updated patch and bulletin were posted.
We recommend that customers who installed the original version of the Windows 2000 patch install the updated version.
The implementation of the Remote Data Protocol (RDP) in the terminal service in Windows NT 4.0 and Windows 2000 does not correctly handle a particular series of data packets. If such a series of packets were received by an affected server, it would cause the server to fail. The server could be put back into normal service by rebooting it, but any work in progress at the time of the attack would be lost.
It would not be necessary for an attacker to be able to start a session with an affected server in order to exploit this vulnerability – the only prerequisite would be the need to be able to send the correct series of packets to the RDP port on the server.
Patch availability:
Windows NT Server 4.0, Terminal Server Edition:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=33250
Windows 2000 Server and Advanced Server:
http://www.microsoft.com/downloads/release.asp?ReleaseID=33389
Microsoft Windows 2000 Datacenter Server:
Patches for Windows 2000 Datacenter Server are hardware-specific and available from the original equipment manufacturer.
|