Site Meter Microsoft Talk » Blog Archive » SMB Networking Holes Patched by Microsoft

SMB Networking Holes Patched by Microsoft

by

Microsoft Security

Microsoft Security

Three vulnerabilities in SMB networking were patched in a single update today my Microsoft: MS09-001: Vulnerabilities in SMB Could Allow Remote Code Execution.

Heads up on three updates for networks that have holes, which could leave you vulnerable.

Two of the three vulnerabilities are rated critical for Windows 2000, Windows XP and Windows Server 2003; the third is rated Moderate for those platforms. Two are rated Moderate for Windows Vista and Windows Server 2008, and the third does not affect those platforms at all.

The first vulnerability, SMB Buffer Overflow Remote Code Execution Vulnerability (CVE-2008-4834), is a frightening one: an unauthenticated networking bug. This is the one that doesn’t affect Windows Vista or Server 2008, but on 2000, XP or Server 2003 an unauthenticated user could invoke a remote code execution over the network.

The second vulnerability, SMB Validation Remote Code Execution Vulnerability (CVE-2008-4835), is very similar to the last one: an unauthenticated network vulnerability that can theoretically allow remote code execution, but more likely denial of service.

The third vulnerability, SMB Validation Denial of Service Vulnerability (CVE-2008-4114), is rated Moderate for all platforms. A specially-crafted network request could cause the system to stop responding and then restart.

Head on over to Microsoft Security Bulletin MS09-001 - Critical


2 Responses to “SMB Networking Holes Patched by Microsoft”

  1. Woot! What’s Buzzing Now? » Blog Archive » Microsoft Talk » Blog Archive » Smb Networking Holes Patched By … Says:

    [...] Taylor Swift Set for CSI Guest Appearance Singer and budding actress Taylor Swift will appear in a CSI episode later this season. She’ll play a “a troubled teenager whose parents own a motel.” The episode begins in the present and [. ...[Continue Reading] [...]

  2. Rufus Pang Says:

    Hello, I don’t usually publish feedback on blogs, as I wish to read only. However I discover the article that you’ve written earlier has very insightful information, and I find it very informational. Anyway, I’m questioning whether you are open for hyperlink change, as I hope that we will agree on a mutual hyperlink alternate agreement. Hope to listen to a positive reply from you, and have an excellent day!

Leave a Reply


About Microsoft Talk

My name is Brick ONeil, and I’ve been with the 451 Press Network since March 2007. I’m the new blogger for Microsoft Talk. We’ll be discussing ‘About Microsoft’ itself. What’s happening, who’s coming/going, what new technologies they’re coming out with, updates and upgrades. I’ll try to bring you news each day that impacts your daily life and use of Microsoft products, or just interesting information I think you’ll enjoy

Microsoft Talk Author(s)

Technology Channel Posts

  • Cell Phones + Social Networks = Love?
    [caption id="attachment_262" align="alignnone" width="128" caption="Social Networks"][/caption]Wireless industry ready to interface with Facebook, MySpace and Bebo Everybody at this week's Mobile [...]
  • LG X120 Netbook
    LG Electronics has announced it is launching their newest netbook called the LG X120. The laptop is a cute one with only 10.1″ screen with backlit. Powering it is an Intel Atom processor [...]
  • Uniea Haptique HardShell Case for MacBook
    This hardshell cases for the new MacBook aluminum are made of ABS plastic coupled with soft touch coating. It offers a textured feel, almost leather like, and protects the surface of the laptop [...]
  • Haier shows off it's offerings to the masses
    [caption id="attachment_1757" align="alignnone" width="600" caption="Haier netb ook, G1 and G2"][/caption]The fine folks over at Haier shows off mysterious "NetBooks," Android phones Haier's [...]
  • Hackers target Gamers
    [caption id="attachment_887" align="alignnone" width="128" caption="Xbox"][/caption]Although I'm not a gamer, everyone should be aware of hackers and malware. According to microsoft, What's the [...]
  • Microsoft Equips Individuals With New Training Resources Needed for Jobs
    [caption id="attachment_733" align="alignnone" width="109" caption="Microsoft"][/caption]Second time around for this bit of news, but very apropos in today's business climate. Microsoft Corp. [...]
  • LG Phone's Transparent Keypad Expected to "Make A New Fashion Statement"
    [caption id="attachment_259" align="alignnone" width="950" caption="Transluscent Phone"][/caption][caption id="attachment_258" align="alignnone" width="500" caption="LG GD-900"][/caption]Firmware or [...]
  • Preorder Nokia N86 at Expansys
    [caption id="attachment_1754" align="alignnone" width="162" caption="Nokia N86"][/caption]Engadget breaks this story: European markets can expect to see Nokia's N86 handset on or about July 22, [...]
  • Microsoft Tests Vista SP2, Readies Windows 7 Updates
    [caption id="attachment_884" align="alignnone" width="116" caption="Vista"][/caption]Lots coming out of Redmond these days. Service Pack 2 for Windows Vista and Windows Server 2008 is reportedly [...]
  • Five Steps to an E-friendly Résumé
    [caption id="attachment_730" align="alignnone" width="128" caption="Resume on Outlook"][/caption]With today's economy and layoffs, we all need all the help we can get when searching for jobs. MSN [...]

Hot Off The Press