New Blaster patch

Sharky Forums


Results 1 to 2 of 2

Thread: New Blaster patch

  1. #1
    Hammerhead Shark Tekime's Avatar
    Join Date
    Dec 2001
    Location
    Falmouth, ME
    Posts
    2,347

    New Blaster patch

    A new patch has been released by Microsoft which supercedes the original patch for RPC vulnerability that blaster took advantage of.

    Link

    Sorry if this has been posted already.

    According to The Register:

    The July patch is effective at stopping the flaw Blaster exploits. The trouble is there are more than one flaw with Microsoft's implementation of an RPC interface for Distributed Component Object Model services (DCOM). This gives rise to security vulnerabilities not fixed by the first patch.

    According to Microsoft's revised bulletin, it turns out there are "three identified vulnerabilities" in the RPCSS Service that deal with DCOM activation - two that could allow arbitrary code execution and one that could result in a denial of service.

    "An attacker who successfully exploited these vulnerabilities could be able to run code with local system privileges on an affected system, or could cause the RPCSS Service to fail. The attacker could then be able to take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges," Microsoft warns.
    So the first patch should take care of Blaster, but there are other vulnerabilities not patched.
    Last edited by Tekime; 09-10-2003 at 04:15 PM.
    Stuff and stuff

  2. #2
    Zoom-Zoom! soupnazi's Avatar
    Join Date
    May 2002
    Location
    Vancouver, BC
    Posts
    15,097
    Thanks for the heads up.
    Spoiler

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •