More holes leave companies vulnerable

By
Follow google news

Various infosecurity companies have rated several of Microsoft’s recently released vulnerabilities as extremely severe and are warning companies to install patches against them.

Internet Security Systems' (ISS) X-Force researchers have classified four of the software developer's vulnerabilities high-risk, while Symantec considers all the vulnerabilities critical.


The LSASS Vulnerabiliity, in the view of Symantec security experts, is one of the most severe. A buffer overflow vulnerability exists in the Local Security Authority Subsystem Service (LSASS). Basically, if this system is breached, a cyber attacker could have the same control of the affected machine as a user or administrator. Files could be stolen or erased, or remote code could be executed on a compromised system, for example.

The LSASS provides an interface for managing local security, domain authentication, and Active Directory processes.

(http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx)

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Popular text editor Notepad++ was hacked to drop malware

Popular text editor Notepad++ was hacked to drop malware

'Moltbook' social media site for AI agents had big security hole

'Moltbook' social media site for AI agents had big security hole

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Under malware threat, runaway AI agent project OpenClaw turns to Google's VirusTotal

Under malware threat, runaway AI agent project OpenClaw turns to Google's VirusTotal

Log In

  |  Forgot your password?