Friday, April 13, 2007

New Microsoft Advisory - RPC Vuln Against DNS Server

April 12th

Microsoft is investigating new public reports of a limited attack exploiting a vulnerability in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2. Microsoft Windows 2000 Professional Service Pack 4, Windows XP Service Pack 2, and Windows Vista are not affected as these versions do not contain the vulnerable code.

http://www.microsoft.com/technet/security/advisory/935964.mspx

-----------------------------

As expected, eEye released this information about this new vuln...

Microsoft DNS Servers are currently being attacked by a zero-day stack-based
buffer overflow. eEye Research is currently investigating the vulnerability and exploitation.
Anyone out there know anything about this?

Looks like those offshore Office Zero-day finders found a better target this time around...

No comments:

Post a Comment