two
Volume 5, Number 16 -- April 23, 2008

Windows Flaw Prompts Security Advisory from Microsoft

Published: April 23, 2008

by Alex Woodie

Public reports of a newly discovered elevation of privilege vulnerability in Windows prompted Microsoft to issue a security advisory last week. Microsoft says customers running the IIS Web server and SQL Server database could be most at risk, and that it's working on a patch.

In Security Advisory 951306, Microsoft says the flaw could be exploited by running specially crafted code on affected machines running Windows XP Professional (but not XP Home Edition), and most editions of Windows Server 2003, Windows Vista, and Windows Server 2008.

Microsoft says the flaw can be exploited if malicious code in the context of the NetworkService or LocalService accounts gains access to resources in processes that are also running as NetworkService or LocalService.

IIS, SQL Server, and Windows Server 2003 are particularly at risk from the new vulnerability, the company says. Any company running user-supplied code on IIS or SQL Server could be at risk. Additionally, the Microsoft Distributed Transaction Coordinator (MSDTC) service provides another avenue for attack in Windows Server 2003; this vector is not a threat in Windows Server 2008 or Windows Vista, Microsoft says.

Microsoft says it's working to fix the problem, either through a service pack, the monthly Patch Tuesday security update process, or through an out-of-band patch.

In the meantime, Microsoft recommends users work around the problem by specifying a WPI (Worker Process Identity) for an application pool.

For more information, see www.microsoft.com/technet/security/advisory/951306.mspx.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
MKS

Meet Your IT Audit and Compliance Demands with MKS

One Seamless Solution for System i and Distributed Application Lifecycle Management

Are you struggling to meet IT audit and compliance demands?
Do you need traceability over software change?

When Pennsylvania Housing Finance Agency (PHFA) needed to achieve compliance, they turned to MKS for traceability over their software change. MKS Integrity enforces their development process and brings end to end traceability to their System i and distributed development operations.

Read the PHFA story.

MKS can help you establish and enforce any software process or workflow, and manage software change from project start to finish. With MKS you can ensure that the application you develop is deployed securely and that only authorized changes go into production.

For auditing and compliance needs, it doesn't get any better than MKS.

For more info, visit http://www.mks.com/itjungle/weareone or call 1 800 613 7535.

Make the Move to MKS now and SAVE!

For a limited time MKS will help you make the move from your existing software change and configuration management solution, with special pricing when you purchase Implementer with MKS Integrity - giving you integrated workflow, complete audit trails and coverage of the application lifecycle as well as a platform to manage both System i and cross-platform development.

Visit the Products section of www.mks.com for more information on Implementer and MKS Integrity.

Click here to request more information on our time limited "change up" offer.

The time is now to make the switch.

Call MKS today at 1-800-613-7535 to discuss your options, and while you're at it,
request a FREE change management process assessment by our team of experts
with over 40 years of experience in the midrange market.

Contact MKS Sales at 1-800-613-7535 or sales@mks.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2009 conference, April 26 - April 30, in Reno, Nevada
LANSA:  It's Time for 4 days of education at the LANSA User Conference, May 4 – 7, in Orlando
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
IBM Expands VIP to All Systems for Precision Sales

Power Systems Adds New Choices for IBM's Academic Initiative

IBM's Q1 Driven by Mainframes, Unix, Services, and the Weak Dollar

The X Factor: Everybody Wants Citrix Systems?

HP Goes Visual with Application Modernization Tools

The Linux Beacon
Canonical Launches Ubuntu 8.04 with Long Term Support

Novell Puts Out JEOS Beta, Starts Appliance Effort

Server Makers Start Shipping Barcelona Boxes

The X Factor: Everybody Wants Citrix Systems?

IBM's Q1 Driven by Mainframes, Unix, Services, and the Weak Dollar

Four Hundred Stuff
Industrial Strength Software Debuts DB2/400 Optimization Tools

Turning a System i into a Time Machine: Nippon Express and CCSS Show How It's Done

inFORM Helps Save the Earth with Updates to i-Based Document Management

United Computer Group Sailing Smooth Through Rough Water

Enterprise Features Gain Focus as MySQL 5.1 Nears Release

Big Iron
IBM's Q1 Driven by Mainframes, Unix, Services, and the Weak Dollar

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
More about SQL and Logical Files

Performance Advice from a Mysterious Friend, Part 5

Admin Alert: V6R1 Changes for the i5/OS Administrator, Part 2

System i PTF Guide
April 19, 2008: Volume 10, Number 16

April 12, 2008: Volume 10, Number 15

April 5, 2008: Volume 10, Number 14

March 29, 2008: Volume 10, Number 13

March 22, 2008: Volume 10, Number 12

March 15, 2008: Volume 10, Number 11

The Unix Guardian
Sun Plans to Scale T2+ Servers to Four Sockets, Maybe More

And Then There Was One: The New and Improved Power 570

Sundry Power Systems Announcements

As I See It: Goldilocks and the Zen of IT

Server Makers Start Shipping Barcelona Boxes

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Solidcore
Danik Consulting
MKS
SafeData
Vibrant Technologies


Printer Friendly Version


TABLE OF CONTENTS
Dynamics CRM Online Is Now Online

Decline In Vulnerabilities Belies Threat Increase, Microsoft Says in New Security Report

Ballmer Downplays Yahoo's Financial Results

Intel Profits Hit, AMD Books a Loss in Recent Quarters

Server Makers Start Shipping Barcelona Boxes

But Wait, There's More:

Microsoft Extends RFID to Mobile Devices . . . Microsoft and Novell to Push Linux, Windows CCS in China . . . Windows Flaw Prompts Security Advisory from Microsoft . . . Windows XP SP3 Released to Manufacturing . . . Enterprise Features Gain Focus as MySQL 5.1 Nears Release . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement