More holes leave companies vulnerable

By

Various infosecurity companies have rated several of Microsoft’s recently released vulnerabilities as extremely severe and are warning companies to install patches against them.

Internet Security Systems' (ISS) X-Force researchers have classified four of the software developer's vulnerabilities high-risk, while Symantec considers all the vulnerabilities critical.


The LSASS Vulnerabiliity, in the view of Symantec security experts, is one of the most severe. A buffer overflow vulnerability exists in the Local Security Authority Subsystem Service (LSASS). Basically, if this system is breached, a cyber attacker could have the same control of the affected machine as a user or administrator. Files could be stolen or erased, or remote code could be executed on a compromised system, for example.

The LSASS provides an interface for managing local security, domain authentication, and Active Directory processes.

(http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx)

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

CBA using facial recognition logins to verify disputed payments

CBA using facial recognition logins to verify disputed payments

Researchers demo AI-crippling GPUHammer attack

Researchers demo AI-crippling GPUHammer attack

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Google Gemini for Workspace vulnerable to prompt injection attacks

Google Gemini for Workspace vulnerable to prompt injection attacks

Log In

  |  Forgot your password?