Critical Patch
If you are running Windows NT 4.0, Windows 2000, Windows
XP or Windows 2003 then continue reading. If you are running Windows 95,
Windows 98, Windows ME or other then this patch won't affect you. (You
should still ensure you have the critical patches in place anyhow.)
Visit
Windows Update to download this patch,
as well as any other critical patches, and update your system. This patch could
be the most serious hole yet found.
Details are scanty in how the buffer overrun could be
exploited but in reading the docs it would appear that anyone who can connect to
your Win NT 4/2000/XP/2003 Server system in any fashion could hack in. Or any
site on the Internet you visit. Or any software or other control or anything you
download when visiting a website. A firewall will *not* make a difference.
"Because this library is widely used by Windows security subsystems, the
vulnerability is exposed through an array of avenues, including Kerberos, NTLMv2
authentication, and applications that make use of certificates (SSL,
digitally-signed e-mail, signed ActiveX controls, etc.)"
Vulnerability
Note VU#583108
eEye Digital Security Advisory AD20040210
eEye Digital Security Advisory AD20040210-2
Microsoft Security Bulletin MS04-007
Microsoft Knowledge Base Article 252648
Visit
Microsoft Security
for more general information on how to protect your computer.
Also make sure your antivirus software is up to
date.
|