Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

More windows vulnerabilities

Options
  • 26-04-2004 6:18pm
    #1
    Registered Users Posts: 18,484 ✭✭✭✭


    On April 22nd, Microsoft became aware of code available on the Internet that seeks to exploit vulnerabilities addressed as part of our April 13th
    security updates. You or someone in your organization has likely received the Bulletin detailing these security updates. As a valued customer, we are
    contacting you again so you have the information and resources you need to help address any security issues that may arise. If you are still evaluating
    or testing these updates, we strongly recommend that you expedite your review and deployment of these updates, or implement the workaround procedures, as
    quickly as possible.



    Microsoft Product Support Alert Details:



    - Microsoft is aware of code available on the Internet that seeks to exploit vulnerabilities addressed as part of our April 13th security updates. We
    are investigating the situation to help protect our customers. Specifically, the reports detail exploit code that attempts to use the IIS PCT/SSL
    vulnerability on servers running Internet Information Services with the Secure Socket Layer authentication enabled. This vulnerability is addressed by
    bulletin MS04-011. Customers who have deployed MS04-011 are not at risk from this exploit code.



    - Microsoft considers these reports credible and serious and continues to urge all customers to immediately install the MS4-011 update as well as the
    other critical updates provided on April 13th.



    - Customers who are still evaluating and testing MS04-011 should immediately implement the workaround steps detailed for the PCT/SSL vulnerability
    detailed in the MS04-011. In addition, Microsoft has published a knowledge base article KB187498 at
    http://support.microsoft.com/default.aspx?scid=kb;en-us;187498 which provides additional details on SSL and how to disable PCT without applying MS04-011.



    - We expect to see additional exploits and proof-of-concept code targeting the April 2004 security bulletin release in coming days and weeks,
    potentially including worm or virus examples.



    If you have any questions regarding the security updates or its implementation after reading the above listed bulletin you should visit
    http://www.microsoft.com/security/incident/pctdisable.asp or contact Microsoft at 0870 60 10 100 (for Northern Ireland customers) or 1850 940 940 (ROI
    customers).





    Thank you,

    Microsoft Ireland Communications Team


Advertisement