Oops!Sixty Nine (69) Win 2000 Security Vulnerabilities Note: Microsoft's Windows 2000 SP4 fixes Six Hundred Fifty (650) Vulnerabilities.
This service pack also reenables the windows update feature in case you disabled it. Frequently contacting the
Microsoft website and its computers without notifying you. Only Microsoft knows what information it is grabbing off your computer. Just another indication of sneaky behavior. We generally recommend
to customers that have spent considerable time "stripping" windows of programs they don't want activated and disabling features that could compromise the system to "leave it alone" if it's working fine. Don't apply service packs.
Rely on your firewall, antivirus software, and what you have done. It's much safer. The full articles on these "Q" numbers are available at the Microsoft Windows 2000 Support Site.
here
.
- Q258060 - Resolved Vulnerability in the SMAPI Port
- Q259166 - UNC Path Can Be Used to Start Programs by Using .chm Files
- Q259622 - Command Processor May Not Parse Excessive Arguments Properly
- Q257870 - Malformed Print Request May Stop Windows 2000 TCP/IP Printing Service
- Q267868 - Renaming CD-ROM Drive Creates Share to Which Everyone Has Full Permission
- Q267866 - Buffer Overflow in Network Monitor May Cause Vulnerability
- Q262388 - Denial-of-Service Attack Possible from Linux RPC Client
- Q268082 - DNS SOA Record May Reveal Administrator Account Name
- Q264345 - False URL Can Steal or Set Cookies for Different Domain
- Q260197 - Interactive Logon Allows Unauthorized Actions in Desktop Process
- Q260219 - High Encryption Pack Does Not Protect Windows 2000 Private Keys
- Q260927 - Windows 2000 with Blank Administrator Password Vulnerable During Setup
- Q266794 - Windows 2000 SNMP Registry Entries Are Saved in Plain Text Format and Are Readable
- Q262694 - Malicious User Can Shut Down Computer Browser Service
- Q260853 - Security Concern with Share-Level Security and Terminal Services
- Q269523 - Service Control Manager Named Pipe Impersonation Vulnerability
- Q269239 - NetBIOS Vulnerability May Cause Duplicate Name on the Network Conflicts
- Q262509 - Patch Available for the Frame Domain Verification, Unauthorized Cookie Access, Malformed Component Attribute, and WPAD Spoofing Vulnerabilities
- Q269049 - Registry-Invoked Programs Use Standard Search Path
- Q267868 - Renaming CD-ROM Drive Creates Administrators Share to Which Everyone Has Full Permission
- Q272743 - HTML E-mail Link Transmits User Name and Password to Unauthorized Server
- Q272303 - RPC Server Service Stops Responding if a malicious user transmits a malformed Remote Procedure Call (RPC) client packet
- Q271641 - The Configure Your Computer Wizard Sets Blank Recovery Mode Password
- Q272736 - Windows 2000 Still Image Service Exposes User Elevation Vulnerability
- Q281492 - Windows Installer Allows Files To Be Written to NTFS Protected Directories
- Q282806 Telnet Service Prevents an Idle Telnet Session from Timing Out
- Q285156 Windows 2000 Event Viewer Contains an Unchecked Buffer
- Q285851 Patch Available for Network DDE Agent Request Vulnerability
- Q285985 Patch Available for New Variant of File Fragment Reading via .HTR Vulnerability
- Q286043 Patch Available for Telnet Logging Vulnerability
- Q287397 Patch Available for Malformed Domain Controller Service Request Vulnerability
- Q287912 Predictable Named Pipes Could Enable Privilege Elevation with Telnet
- Q288855 FTP Service Allows Login to Domain Guest Account
- Q289243 Forged SID Could Result in Elevated Privileges in Windows 2000
- Q289782 INFO: Post Windows 2000 Service Pack 2 COM+ Rollup Hotfix 8 Is Available
- Q292435 Invalid RDP Data Can Cause Memory Leak in Terminal Services
- Q293826 Pattern-Matching Function Can Cause Access Violation on FTP Server
- Q294370 Updated Patch for Microsoft Security Bulletin MS00-060
- Q294379 Addressees Appear in Body of SMTP Message Instead of the Header If You Specify Many Addressees
- Q294391 Malformed Request to Domain Controller Can Cause Memory Exhaustion
- Q294774 IIS Loads ISAPI Extension In-Process Even When Application Is Marked for High Isolation
- Q295534 Superfluous Decoding Operation Can Allow Command Execution Through IIS
- Q296185 Patch Available for New Variant of the "Malformed Hit-Highlighting" Vulnerability
- Q297860 IIS 5.0 Security and Post-Windows NT 4.0 SP5 IIS 4.0 Patch Rollup
- Q298009 Cipher.exe Security Tool for the Encrypting File System
- Q298012 Malformed RPC Request Can Cause Service Problems
- Q298340 Patch Available for WebDAV Denial of Service
- Q299553 Logon Command That Contains a Particular Malformation Causes an Access Violation in the Telnet Service
- Q299687 Function Exposed By Using LDAP over SSL Could Enable Passwords to Be Changed
- Q299796 Denial-of-Service Attack on Port 1720 May Cause a Memory Leak in Conf.exe
- Q300477 FPSE: Potential Buffer Overrun Vulnerability in Visual Studio RAD (Remote Application Deployment)
- Q300855 Windows 2000 Telnet Security Rollup
- Q300901 Telnet Service Allows Logging On to Domain Guest Account
- Q300905 Handle Leak in Telnet Service Causes a Denial-of-Service Vulnerability
- Q300908 Program Running with Normal Privileges Can Terminate a Telnet Session
- Q300972 Unchecked Buffer in Index Server ISAPI Extension Can Enable Web Server Compromise
- Q301625 Patch Available for SSI Privilege Elevation Vulnerability
- Q302755 Authentication Error in SMTP Service Could Allow Mail Relaying
- Q303984 NNTP Service in Windows 2000 Contains a Memory Leak
- Q304867 Patch Available for MIME Header Denial of Service Vulnerability
- Q305601 FIX: CRT String Format Functions May Underwrite Buffer
- Q306118 FPSE2000: List of Issues Fixed in FrontPage Server Extensions Service Release 1.3
- Q306121 Malformed "Dotless" IP Address Can Cause a Web Page to Be Handled in the Intranet Zone
- Q307454 Invalid RDP Data Can Cause Terminal Services Failure
- Q308268 IDA and .IDQ Mappings Restored After You Install Service Pack or Add/Remove a Windows Component
- Q308414 Patch Available for HTTP Request Encoding Vulnerability
- Q311355 The Danish Version of Security Hotfix MS01-041 Is Not Installed
- Q311371 Terminal Services Sessions Are Disconnected Because of a Decryption Error
- Q315404 Clients with an Expired Temporary License May Be Unable to Connect to Terminal Services
|