| |
|

|
|

|
|
DirectX
|
|
ActiveMac
|
|
Downloads
|
|
Forums
|
|
Interviews
|
|
News
|
|
MS Games & Hardware
|
|
Reviews
|
|
Support Center
|
|
Windows 2000
|
|
Windows Me
|
|
Windows Server 2003
|
|
Windows Vista
|
|
Windows XP
|
|

|
|

|
|

|
|
News Centers
|
|
Windows/Microsoft
|
|
DVD
|
|
Apple/Mac
|
|
Xbox
|
|
News Search
|
|

|
|

|
|

|
|
ActiveXBox
|
|
Xbox News
|
|
Box Shots
|
|
Inside The Xbox
|
|
Released Titles
|
|
Announced Titles
|
|
Screenshots/Videos
|
|
History Of The Xbox
|
|
Links
|
|
Forum
|
|
FAQ
|
|

|
|

|
|

|
|
Windows
XP
|
|
Introduction
|
|
System Requirements
|
|
Home Features
|
|
Pro Features
|
|
Upgrade Checklists
|
|
History
|
|
FAQ
|
|
Links
|
|
TopTechTips
|
|

|
|

|
|

|
|
FAQ's
|
|
Windows Vista
|
|
Windows 98/98 SE
|
|
Windows 2000
|
|
Windows Me
|
|
Windows Server 2002
|
|
Windows "Whistler" XP
|
|
Windows CE
|
|
Internet Explorer 6
|
|
Internet Explorer 5
|
|
Xbox
|
|
Xbox 360
|
|
DirectX
|
|
DVD's
|
|

|
|

|
|

|
|
TopTechTips
|
|
Registry Tips
|
|
Windows 95/98
|
|
Windows 2000
|
|
Internet Explorer 5
|
|
Program Tips
|
|
Easter Eggs
|
|
Hardware
|
|
DVD
|
|

|
|

|
|

|
|
ActiveDVD
|
|
DVD News
|
|
DVD Forum
|
|
Glossary
|
|
Tips
|
|
Articles
|
|
Reviews
|
|
News Archive
|
|
Links
|
|
Drivers
|
|

|
|

|
|

|
|
Latest Reviews
|
|
Xbox/Games
|
|
Halo 3
|
Call of Juarez
|
|

|
|
Applications
|
|
Adobe Illustrator CS3
|
|

|
|
Hardware
|
|
Athlon 64 X2 6000+
|
|
Acer Ferrari 5000
|
|

|
|

|
|

|
|
Latest Interviews
|
|
Steve Ballmer
|
|
Jim Allchin
|
|

|
|

|
|

|
|
Site News/Info
|
|
About This Site
|
|
Affiliates
|
|
Contact Us
|
|
Default Home Page
|
|
Link To Us
|
|
Links
|
|
Member Pages
|
|
News Archive
|
|
Site Search
|
|
Awards
|
|

|
|

|
|

|
|
Credits
©1997/2007, Active Network, Inc. All Rights Reserved.
Layout, & Design by Byron Hinson. Content written by the Active Network team. Please click
here
for full terms of use and restrictions or read our
Privacy
Statement.
|
|
|
 |
|
Microsoft
Security Bulletin Summary List 2002
|
Security Bulletin Name,
Brief Description
|
ID Number, Date/Link
|
Unchecked Buffer in Windows Shell Could Enable
System Compromise: The Windows Shell is responsible for
providing the basic framework of the Windows user interface
experience. It is most familiar to users as the Windows Desktop, but
also provides a variety of other functions to help define the user's
computing session, including organizing files and folders, and
providing the means to start applications.
An unchecked buffer exists in one of the functions used
by the Windows Shell to extract custom attribute information from
audio files. A security vulnerability results because it is possible
for a malicious user to mount a buffer overrun attack and attempt to
exploit this flaw. |
(MS02-072) |
|
December 18, 2002 |
|
|
(MS02-071) |
|
December 12, 2002 |
|
|
(MS02-070) |
|
December 12, 2002 |
|
|
(MS02-069) |
|
December 12, 2002 |
|
|
(MS02-068) |
|
December 04, 2002 |
|
|
(MS02-067) |
|
December 04, 2002 |
|
|
(MS02-066) |
|
November 20, 2002 |
|
|
(MS02-065) |
|
November 20, 2002 |
|
|
(MS02-064) |
|
October 31, 2002 |
|
|
(MS02-063) |
|
October 31, 2002 |
|
|
(MS02-062) |
|
October 31, 2002 |
|
|
(MS02-061) |
|
October 16, 2002 |
|
|
(MS02-060) |
|
October 16, 2002 |
|
|
(MS02-059) |
|
October 16, 2002 |
|
|
(MS02-058) |
|
October 12, 2002 |
|
|
(MS02-057) |
|
October 2, 2002 |
|
Cumulative Patch for SQL Server:
|
(MS02-056) |
|
October 02, 2002 |
|
Unchecked Buffer in Windows Help Facility Could Enable
Code Execution: |
(MS02-055) |
|
October 02, 2002 |
|
Unchecked Buffer in File Decompression Functions Could
Lead to Code Execution: |
(MS02-054) |
|
October 02, 2002 |
|
|
(MS02-053) |
|
September 25, 2002 |
|
Flaw in Microsoft VM JDBC Classes Could Allow Code Execution:
|
(MS02-052) |
|
September 18, 2002 |
|
Cryptographic Flaw in RDP Protocol can Lead to Information
Disclosure: |
(MS02-051) |
|
September 18, 2002 |
|
Certificate Validation Flaw Could Enable Identity Spoofing:
|
(MS02-050) |
|
September 04, 2002 |
|
Flaw Could Enable Web Page to Launch Visual FoxPro 6.0
Application Without Warning: |
(MS02-049) |
|
September 04, 2002 |
|
Flaw in Certificate Enrollment Control Could Allow Deletion
of Digital Certificates: |
(MS02-048) |
|
August 28, 2002 |
|
Cumulative Patch for Internet Explorer:
|
(MS02-047) |
|
August 22, 2002 |
|
Buffer Overrun in TSAC ActiveX Control Could Allow Code
Execution: |
(MS02-046) |
|
August 22, 2002 |
|
|
(MS02-045) |
|
August 22, 2002 |
Unsafe Functions in Office Web Components:
The Office Web Components (OWC) contain several ActiveX controls
that give users limited functionality of Microsoft Office in a web browser
without requiring that the user install the full Microsoft Office application.
This allows users to utilize Microsoft Office applications in situations
where installation of the full application is infeasible or undesirable.
The control contains three security vulnerabilities, each
of which could be exploited either via a web site or an HTML mail.
The vulnerabilities result because of implementation errors in the following
methods and functions the controls expose: |
(MS02-044) |
|
August 21, 2002 |
|
Cumulative Patch for SQL Server:
|
(MS02-043) |
|
August 14, 2002 |
|
Flaw in Network Connection Manager Could Enable Privilege
Elevation: |
(MS02-042) |
|
August 14, 2002 |
|
Unchecked Buffer in Content Management Server Could Enable
Server Compromise: |
(MS02-041) |
|
July 31, 2002 |
|
Unchecked Buffer in MDAC Function Could Enable SQL Server
Compromise: |
(MS02-040) |
|
July 31, 2002 |
|
Buffer Overruns in SQL Server 2000 Resolution Service Could
Enable Code Execution: |
(MS02-039) |
|
July 24, 2002 |
|
Unchecked Buffer in SQL Server 2000 Utilities Could Allow
Code Execution: |
(MS02-038) |
|
July 24, 2002 |
|
Server Response To SMTP Client EHLO Command Results In
Buffer Overrun: |
(MS02-037) |
|
July 24, 2002 |
|
Authentication Flaw in Microsoft Metadirectory Services
Could Allow Privilege Elevation: |
(MS02-036) |
|
July 24, 2002 |
|
SQL Server Installation Process May Leave Passwords on
System: |
(MS02-035) |
|
July 11, 2002 |
|
Cumulative Patch for SQL Server: This is
a cumulative patch that includes the functionality of all previously released
patches for SQL Server 2000. In addition, it eliminates three newly discovered
vulnerabilities affecting SQL Server 2000 and MSDE 2000 (but not any previous
versions of SQL Server or MSDE): - - A buffer overrun vulnerability in
a procedure used to encrypt SQL Server credential information. An attacker
who was able to successfully exploit this vulnerability could gain significant
control over the database and possibly the server itself depending on
the account SQL server runs as. - - A buffer overrun vulnerability in
a procedure that relates to the bulk inserting of data in SQL Server tables.
An attacker who was able to successfully exploit this vulnerability could
gain significant control over the database and possibly the server itself.
- - A privilege elevation vulnerability that results because of in- correct
permissions on the Registry key that stores the SQL Server service account
information. An attacker who was able to success- fully exploit this vulnerability
could gain greater privileges on the system than had been granted by the
system administrator -- potentially even the same rights as the operating
system. |
(MS02-034) |
|
July 11, 2002 |
|
Unchecked Buffer in Profile Service Could Allow Code Execution
in Commerce Server: |
(MS02-033) |
|
June 26, 2002 |
|
Cumulative Patch for Windows Media Player:
|
(MS02-032) |
|
June 26, 2002 |
|
Cumulative Patches for Excel and Word for Windows:
|
(MS02-031) |
|
June 19, 2002 |
|
Unchecked Buffer in SQLXML Could Lead to Code Execution:
|
(MS02-030) |
|
June 12, 2002 |
|
Unchecked Buffer in Remote Access Service Phonebook Could
Lead to Code Execution: |
(MS02-029) |
|
June 12, 2002 |
|
Heap Overrun in HTR Chunked Encoding Could Enable Web Server
Compromise:
|
(MS02-028) |
|
June 12, 2002 |
|
Unchecked Buffer in Gopher Protocol Handler Can Run
Code of Attacker's Choice: There is an unchecked buffer
in a piece of code which handles the response from Gopher servers. This
code is used independently in IE, ISA, and Proxy Server. A security vulnerability
results because it is possible for an attacker to attempt to exploit this
flaw by mounting a buffer overrun attack through a specially crafted server
response. The attacker could seek to exploit the vulnerability by crafting
a web page that contacted a server under the attacker's control. The attacker
could then either post this page on a web site or send it as an HTML email.
When the page was displayed and the server's response received and processed,
the attack would be carried out. A successful attack requires that the
attacker be able to send information to the intended target. Anything
which inhibited connectivity could protect against attempts to exploit
this vulnerability. In the case of IE, the code would be run in the user's
context. As a result, any limitations on the user would apply to the attacker's
code as well. |
(MS02-027) |
|
June 11, 2002 |
|
Unchecked Buffer in ASP.NET Worker Process:
ASP.NET provides for session state management through a variety of
modes. One of these modes is StateServer mode. This mode stores session
state information in a separate, running process. That process can run
on the same machine or a different machine from the ASP.NET application.
There is an unchecked buffer in one of the routines that handles the processing
of cookies in StateServer mode. A security vulnerability results because
it is possible for an attacker to seek to exploit it by mounting a buffer
overrun attack. A successful attack could cause the ASP.NET application
to restart. As a result, all current users of the web-based application
would see their current session restart and their current session information
would be lost. The StateServer mode is not the default mode for session
state management in ASP.NET. ASP.NET applications using StateServer mode
that do not use cookies are not vulnerable. |
(MS02-026) |
|
June 06, 2002 |
|
Malformed Mail Attribute can Cause Exchange 2000
to Exhaust CPU Resources: A security vulnerability results because
it is possible for an attacker to seek to exploit this flaw and mount
a denial of service attack. An attacker could attempt to levy an attack
by connecting directly to the Exchange server and passing a raw, hand-crafted
mail message with a specially malformed attribute. When the message was
received and processed by the Store service, the CPU would spike to 100%.
The effects of the attack would last as long as it took for the Exchange
Store service to process the message. Neither restarting the service nor
rebooting the server would remedy the denial of service. |
(MS02-025) |
|
May 29, 2002 |
|
Authentication Flaw in Windows Debugger can Lead
to Elevated Privileges: The Windows debugging facility provides
a means for programs to perform diagnostic and analytic functions on applications
as they are running on the operating system. One of these capabilities
allows for a program, usually a debugger, to connect to any running program,
and to take control of it. The program can then issue commands to the
controlled program, including the ability to start other programs. These
commands would then execute in the same security context as the controlled
program. There is a flaw in the authentication mechanism for
the debugging facility such that an unauthorized program can gain access
to the debugger. A vulnerability results because an attacker can use this
to cause a running program to run a program of her choice. Because many
programs run as the operating system, this means that an attacker can
exploit this vulnerability to run code as the operating system itself.
She could take any action on the system including deleting data, adding
accounts with administrative access, or reconfiguring the system. |
(MS02-024) |
|
May 22, 2002 |
|
Cumulative Patch for Internet Explorer:
|
(MS02-023) |
|
May 15, 2002 |
|
Unchecked Buffer in MSN Chat Control Can Lead to Code Execution:
|
| |