Microsoft has just released the Windows 2000 and Windows XP patches that fix the unchecked buffer issue in SNMP service. Simple Network Management Protocol (SNMP) is an Internet standard protocol for managing disparate network devices such as firewalls, computers, and routers. All versions of Windows except Windows ME provide an SNMP implementation, which is neither installed nor running by default in any version. A buffer overrun is present in all implementations. By sending a specially malformed management request to a system running an affected version of the SNMP service, an attacker could cause a denial of service. In addition, it is possible that he could cause code to run on the system in LocalSystem context. This could potentially give the attacker the ability to take any desired action on the system.
Patches for other platforms are under development and will be available shortly. When this happens, we will re-release this bulletin with information on how to obtain and install these patches.
|