All the latest UK technology news, reviews and analysis

Critical Windows 2000 flaw found

by Iain Thomson

More from this author

18 Mar 2003

Be the first to comment

  • Tweet this

Windows 2000 users need to patch their systems immediately to avoid hackers taking control, Microsoft has warned.

Users have discovered a flaw in the operating system's implementation of the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol.

WebDAV provides a standard for editing and file management between computers on the internet using HTTP, and is commonly used to manage web servers remotely.

If a hacker sends a specially crafted HTTP request to a server running IIS they can either shut down the server or cause it to run their code.

The flaw is not related to the new version of CodeRed II that also attacks IIS servers.

"A few customers found out about this last week and let us know," said Simon Conant, security specialist for Microsoft.

"We've been quick to write, test and release the patch and, although the problem hasn't spread, it wouldn't hurt to be fully patched."

But unusually the patch was released as the sole item in the announcement, rather than as part of a bundle of patches. This gives an indication of how seriously Microsoft is taking the problem.

Security consultants are warning the flaw is serious.

"We have verified the existence of a functional exploit tool," said Internet Security Systems' X-Force in a statement.

"This vulnerability is in itself very serious, but the existence of robust exploits in the wild dictates that fixes or temporary workarounds should be applied immediately."

Although Microsoft has supplied a patch for this vulnerability and recommends customers to install it immediately, additional tools and preventive measures have been provided to block the exploitation of this vulnerability while the software giant assesses the impact and compatibility of the patch.

Microsoft pointed to the following mitigating factors:

  • URLScan, which is a part of the IIS Lockdown Tool, will block this attack in its default configurations.
  • The vulnerability can only be exploited remotely if an attacker can establish a web session with an affected server.

A patch for all PCs except Japanese NEC boxes (which use a different x86 architecture) is available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Design Architect (Windows Database Application)

Software Design Architect (Windows Database Application...

Lead Java Developer - Mobile- Digital- Amsterdam

Lead Java Developer - Fast growing, young and international...

Graduate Software Support Engineer

Job Specification Graduate Support Engineer...

c# or asp.net Software Developer

Job Specification For: Software Developer...

To send to more than one email address, simply separate each address with a comma.