Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Over the Horizon>Missing Microsoft patches, part II

Missing Microsoft patches, part II

Tweet

Chris mosby By Chris Mosby

After an uneventful patch release earlier this month, we are now faced with a few important issues.

The patches themselves are not too serious, but, of course, there are some attacks that Microsoft didn’t get around to patching.


Flaw in Internet Connection Sharing causes DoS

There’s a vulnerability in the NAT (Network Address Translation) Helper Components (ipnathlp.dll) in Windows Internet Connection Sharing (ICS). The flaw can be exploited by a hacker by sending a DNS (Domain Name System) query to a machine that hosts ICS for a shared network. This can cause the Helper components to crash, resulting in a Denial of Service (DoS) of ICS on the shared network.

For this exploit to work, the hacker has to send the infected DNS query from a client machine on the same shared network as the computer that’s hosting ICS. This flaw has been confirmed in a fully patched Windows XP SP2 system, and exploit code is already available on the Web. It’s been reported that other systems may also be affected, but this hasn’t been confirmed.

What to do: ICS has never been the best way to share an Internet connection between computers. A hardware solution, like the hardware firewall suggested in Brian’s Security Baseline, is a far better option.

More information: CVE-2006-5614, Secunia, ISS, SecurityFocus, OSVDB, FrSIRT, SecurityTracker, eEye

Windows Workstation service vulnerable to DoS

There’s a weakness in the Windows Workstation service, which can be exploited by hackers to cause the service to crash. It can also cause a system to be unresponsive by consuming large amounts of memory. This is done by sending specific data to the NetBIOS service, which then triggers a memory allocation error in svchost.exe.

This flaw has been confirmed on fully patched Windows XP SP2 and Windows 2000 SP4 systems. Other systems may be vulnerable, too, but I haven’t seen any definite reports yet.

What to do: This is another example in which Brian’s Security Baseline is a good reference. Using a good hardware firewall should automatically block the traffic that would be needed by this exploit.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. The missing Microsoft patches, part 1
  2. Patches are missing for Word, PowerPoint
  3. Microsoft skips some critical IE patches
  4. Microsoft monthly patches
  5. Black Tuesday leaves several flaws unpatched
= Paid content

All Windows Secrets articles posted on 2007-04-12:

  • Top Story How to get Windows software at half-price
  • LangaList Plus More ways to prevent phantom devices
  • Wacky Web Week Summertime and the living is tasty
  • LangaList Plus Vista SP1 is coming, but not anytime soon
  • Over the Horizon Missing Microsoft patches, part II
  • Patch Watch Patch is released to fix .ani patch
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Easily edit Windows’ right-click context menus 4.09
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb