Microsoft dice, bajo "What’s the scope of the vulnerability?"
Un atacante, que exitosamente ha explotado esta vulnerabilidad puede conseguir control absolute de una computadora remota (la tuya). Esto le daria al atacante la abilidad de tomar cualquier accion en el servidor que ellos quieran. Por ejemplo un atacante puede cambiar paginas web, reformatear tu disco dura o añadir nuevos usuarios al grupo de administradores local.
Para llevar a cabo tal ataque, un atacanted requeriria la abilidad de enviar un mensaje malformado al servicio RPC y asi causar que la maquina deseade falle de tal manera que el codigo arbitrario pueda ser ejecutado.
*****PARA ir DIRECTAMENTE a la website de Microsoft y descargar el PATCH o PROGRAMA que proteje a tu sistema ve a:
http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
A few times a message has appeared on my screen suddenly telling me that NT AUTHORITY/SYSTEM was going to shut down my PC. All you can do is save your work and basically take it like a man unforunately and let your computer reboot.
This is a security flaw in Microsoft Windows, mainly NT/XP/Server.
If you see this message you should install Windows updates as soon as possible. There is basically someone out there sending data to your PC causing this to happen.
Advisory Warning to all users of the following operating systems:
Microsoft Windows NT 4.0
Microsoft Windows NT 4.0 Terminal Services Edition
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Your Microsoft Operating System may potentially be under attack by HACKER ACTIVITY. The vulnerability attack can fool software into accepting insecure commands that could let intruders steal data, delete files or eavesdrop on e-mails.
Due to the seriousness of this vulnerability the Department of Homeland Security and Microsoft encourages system administrators and computer owners to update vulnerable versions of Microsoft Windows operating systems as soon as possible.
Our recommendation is to please go to:
http://microsoft.com/technet/treevi...in/MS03-026.asp to install the patch immediately.
Microsoft Security Bulletin MS03-026
Print
Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
Originally posted: July 16, 2003
Revised: August 12, 2003
Summary
Who should read this bulletin: Users running Microsoft ® Windows ®
Impact of vulnerability: Run code of attacker’s choice
Maximum Severity Rating: Critical
Recommendation: Systems administrators should apply the patch immediately
End User Bulletin: An end user version of this bulletin is available at:
http://www.microsoft.com/security/security_bulletins/ms03-026.asp.
Affected Software:
Not Affected Software:
- Microsoft Windows NT® 4.0
- Microsoft Windows NT 4.0 Terminal Services Edition
- Microsoft Windows 2000
- Microsoft Windows XP
- Microsoft Windows Server™ 2003
- Microsoft Windows Millennium Edition
Technical details
Frequently asked questions
Patch availability
Download locations for this patch
Additional information about this patch
Other information:
AcknowledgmentsMicrosoft thanks The Last Stage of Delirium Research Group for reporting this issue to us and working with us to protect customers.
Support:
- Microsoft Knowledge Base article 823980 discusses this issue and will be available approximately 24 hours after the release of this bulletin. Knowledge Base articles can be found on the Microsoft Online Support web site.
- Technical support is available from Microsoft Product Support Services. There is no charge for support calls associated with security patches.
Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.
Disclaimer:
The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.Revisions:
- V1.0 (July 16, 2003): Bulletin Created.
- V1.1 (July 18, 2003): Mitigating factors and Workaround section updated to reflect additional ports.
- V1.2 (July 21, 2003): Added Windows XP gold patch verification registry key.
- V1.3 (July 27, 2003): Updated Workaround section to include additonal information about how to disable DCOM.
- V1.4 (August 12, 2003): Updated to include information about Windows 2000 Service Pack 2 support for this patch and updated bulletin with additonal workaround information.
Blaster Worm: Critical Security Patch for Windows XP
A security issue has been identified that could allow an attacker to remotely compromise a computer running Microsoft® Windows® and gain complete control over it.
OverviewA security issue has been identified that could allow an attacker to remotely compromise a computer running Microsoft® Windows® and gain complete control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer. |
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
System Requirements
|
![]() |
|
Instructions
|
__________________
Webmaster, Rotary Club Amboró
www.rotaryclubamboro.org
Tel.: 591-3-335-0176
Cel: 721-86774
Santa Cruz de la Sierra - BOLIVIA
