Microsoft Security Bulletin MS04-007

Discussion in 'Computer Security' started by Phil, Feb 11, 2004.

  1. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    ASN.1 Vulnerability Could Allow Code Execution (828028)
    Issued: February 10, 2004
    Version Number: 1.0

    Summary
    Who should read this document: Customers who are using Microsoft® Windows®

    Impact of vulnerability: Remote Code Execution

    Maximum Severity Rating: Critical

    Recommendation: Systems administrators should apply the update immediately.

    Security Update Replacement: None

    Caveats: Windows NT 4.0 (Workstation, Server, and Terminal Server Edition) does not install the affected file by default. This file is installed as part of the MS03-041 Windows NT 4.0 security update and other possible non-security-related hotfixes. If the Windows NT 4.0 security update for MS03-041 is not installed, this may not be a required update. To verify if the affected file is installed, search for the file named Msasn1.dll. If this file is present, this security update is required. Windows Update, Software Update Services, and the Microsoft Security Baseline Analyzer will also correctly detect if this update is required.

    Affected Software:

    Microsoft Windows NT® Workstation 4.0 Service Pack 6a – Download the update.
    Microsoft Windows NT Server 4.0 Service Pack 6a – Download the update.
    Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 – Download the update.
    Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft 2000 Windows Service Pack 4 – Download the update.
    Microsoft Windows XP, Microsoft Windows XP Service Pack 1 – Download the update.
    Microsoft Windows XP 64-Bit Edition, Microsoft Windows XP 64-Bit Edition Service Pack 1 – Download the update.
    Microsoft Windows XP 64-Bit Edition Version 2003, Microsoft Windows XP 64-Bit Edition Version 2003 Service Pack 1 – Download the update.
    Microsoft Windows Server™ 2003 – Download the update.
    Microsoft Windows Server 2003 64-Bit Edition – Download the update.
    Tested Microsoft Windows Components:

    Affected Components:

    Microsoft ASN.1 Library
    The software listed above has been tested to determine if the versions are affected. Other versions either no longer include security update support or may not be affected. Please review the Microsoft Support Lifecycle Web site to determine the support lifecycle for your product and version.

    Further Details :Microsoft Security Bulletin MS04-007
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  2. SimonV
    Honorary Member

    SimonV Petabyte Poster Gold Member

    6,651
    180
    258
    Also:

    Vulnerability in the Windows Internet Naming Service (WINS)
    Windows 2000 (all versions), NT4 Server SP6a Patch, Microsoft Windows Server 2003 Patch
    _______________________________________
    Cumulative Security Update for Internet Explorer (832894)
    _______________________________________
    Critical Update for Windows Media Player (All Versions)
     
    Certifications: MOS Master 2003, CompTIA A+, MCSA:M, MCSE
    WIP: Keeping CF Alive...
  3. Jakamoko
    Honorary Member

    Jakamoko On the move again ...

    9,924
    74
    229
    Cheers for those, Guys :thumbleft
     
    Certifications: MCP, A+, Network+
    WIP: Clarity

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.