|
Hello all: Look at the latest security problem with Windows/NT. Incredible! Why get an AS/400??!!!! Steve Glanstein mic@aloha.com > Microsoft Security Bulletin (MS99-024) > -------------------------------------- > > Patch Available for "Unprotected IOCTLs" Vulnerability > > Originally Posted: July 06, 1999 > > Summary > ======= > Microsoft has released a patch that eliminates a vulnerability that could > allow denial of service attacks against a Microsoft(r) Windows NT(r) > workstation, server or terminal server. An unprivileged program can disable > the local mouse or keyboard on a server or workstation, and disable the > console mouse or keyboard on a terminal server. > > Frequently asked questions regarding this vulnerability can be found at > http://www.microsoft.com/security/bulletins/MS99-024faq.asp > > Issue > ===== > The IOCTLs that are used to obtain services from the keyboard and mouse > drivers in Windows NT do not require that the calling program have > administrative privileges. A user-level program could use legitimate calls > to disable the mouse and keyboard, after which the machine would need to be > rebooted to restore normal service. On a terminal server, such a program > could disable the keyboard and mouse on the console. > > Affected Software Versions > ========================== > - Microsoft Windows NT Workstation 4.0 > - Microsoft Windows NT Server 4.0 > - Microsoft Windows NT Server 4.0, Enterprise Edition > - Microsoft Windows NT Server 4.0, Terminal Server Edition > > Patch Availability > ================== > - Windows NT Server and Workstation 4.0: > ftp://ftp.microsoft.com/bussys/winnt/winnt-public/ > fixes/usa/nt40/Hotfixes-PostSP5/IOCTL-fix/ > - Windows NT Server 4.0, Terminal Server Edition: > ftp://ftp.microsoft.com/bussys/winnt/winnt-public/ > fixes/usa/nt40tse/Hotfixes-PostSP4/IOCTL-fix/ > > NOTE: Line breaks have added to the above URLs for readability +--- | This is the Midrange System Mailing List! | To submit a new message, send your mail to MIDRANGE-L@midrange.com. | To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com. | To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com. | Questions should be directed to the list owner/operator: david@midrange.com +---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.