More holes leave companies vulnerable

By
Follow google news

Various infosecurity companies have rated several of Microsoft’s recently released vulnerabilities as extremely severe and are warning companies to install patches against them.

Internet Security Systems' (ISS) X-Force researchers have classified four of the software developer's vulnerabilities high-risk, while Symantec considers all the vulnerabilities critical.


The LSASS Vulnerabiliity, in the view of Symantec security experts, is one of the most severe. A buffer overflow vulnerability exists in the Local Security Authority Subsystem Service (LSASS). Basically, if this system is breached, a cyber attacker could have the same control of the affected machine as a user or administrator. Files could be stolen or erased, or remote code could be executed on a compromised system, for example.

The LSASS provides an interface for managing local security, domain authentication, and Active Directory processes.

(http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx)

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

ServiceNow nears deal to buy cyber security startup

ServiceNow nears deal to buy cyber security startup

Services Australia may get powers to rein in data breach exposure

Services Australia may get powers to rein in data breach exposure

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Home Affairs to unleash AI on sensitive government data

Home Affairs to unleash AI on sensitive government data

Log In

  |  Forgot your password?