Vulnerability Bulletins |
Actualización Crítica para Microsoft RPC/DCOM |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Compromiso Root |
Dificulty | Experto |
Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
Property | Value |
Affected manufacturer | Microsoft |
Affected software |
Microsoft Windows NT Workstation 4.0 Service Pack 6a Microsoft Windows NT Server 4.0 Service Pack 6a Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 Microsoft Windows 2000 Service Pack 2 Microsoft Windows 2000 Service Pack 3 Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP Microsoft Windows XP Service Pack 1 Microsoft Windows XP 64-Bit Edition Service Pack 1 Microsoft Windows XP 64-Bit Edition Version 2003 Microsoft Windows Server 2003 Microsoft Windows Server 2003 64-Bit Edition |
Description |
|
Microsoft ha publicado una actualización de seguridad que soluciona múltiples vulnerabilidades. La explotación de las más críticas de las vulnerabilidades podrían permitir a un atacante remoto conseguir el control completo del sistema afectado. Las vulnerabilidades son las siguientes: Vulnerabilidad en RPC Runtime Library - CAN-2003-0813 Afecta a: Windows 2000, Windows XP, Windows Server 2003 Impacto: Ejecución Remota de Código Vulnerabilidad en el Servicio RPCSS - CAN-2004-0116 Afecta a: Windows 2000, Windows XP, Windows Server 2003 Impacto: Denegación de Servicio Vulnerabilidad en COM Internet Services (CIS) – RPC sobre HTTP - CAN-2003-0807 Afecta a: Windows NT Server 4.0, Windows NT Server 4.0, Terminal Server Edition, Windows 2000, Windows Server 2003 Impacto: Denegación de Servicio Vulnerabilidad en Object Identity (Identidades de objetos) - CAN-2004-0124 Afecta a: Windows 98, 98 SE, ME, Windows NT Workstation 4.0, Windows NT Server 4.0, Windows NT Server 4.0, Terminal Server Edition, Windows 2000, Windows XP, Windows Server 2003 Impacto: Escape de información |
|
Solution |
|
Actualización de software Microsoft Windows Microsoft Windows NT Workstation 4.0 Service Pack 6a http://www.microsoft.com/downloads/details.aspx?FamilyId=4ACB5BD6-A0BF-40BC-8955-D833923642EF Microsoft Windows NT Server 4.0 Service Pack 6a http://www.microsoft.com/downloads/details.aspx?FamilyId=D4F2AD32-FE74-4DA1-AEAE-80897AC86720 Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 http://www.microsoft.com/downloads/details.aspx?FamilyId=5B29E35D-E5DA-4486-B7EB-D54C7398142C Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4 http://www.microsoft.com/downloads/details.aspx?FamilyId=FBD38C36-D1D3-47A2-A5D5-6C8F27FDCC40 Microsoft Windows XP and Microsoft Windows XP Service Pack 1 http://www.microsoft.com/downloads/details.aspx?FamilyId=D488BBBB-DA77-448D-8FF0-0A649A0D8FC3 Microsoft Windows XP 64-Bit Edition Service Pack 1 http://www.microsoft.com/downloads/details.aspx?FamilyId=4C3ED21D-FF40-4C9D-99DD-1632E43C1645 Microsoft Windows XP 64-Bit Edition Version 2003 http://www.microsoft.com/downloads/details.aspx?FamilyId=75A08528-5E99-4BE0-8E97-F1C9789611EB Microsoft Windows Server 2003 http://www.microsoft.com/downloads/details.aspx?FamilyId=07317CE9-520D-4574-B575-5FB85DA9A4D7 Microsoft Windows Server 2003 64-Bit Edition http://www.microsoft.com/downloads/details.aspx?FamilyId=75A08528-5E99-4BE0-8E97-F1C9789611EB |
|
Standar resources |
|
Property | Value |
CVE |
CAN-2003-0813 CAN-2004-0116 CAN-2003-0807 CAN-2004-0124 |
BID | |
Other resources |
|
Microsoft Security Bulletin MS04-012 http://www.microsoft.com/technet/security/Bulletin/MS04-012.mspx |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2004-04-14 |