New cumulative Microsoft patch fixes two critical threats

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS
At the end of March, Microsoft released Security Bulletin MS02-015. This is a cumulative patch that includes new patches for two critical threats, including the CodeBase Localpath vulnerability. The bulletin refers to this vulnerability as Local Executable Invocation via ObjectTag, but it's the same as the CodeBase Localpath vulnerability (CAN-2002-0077). The other critical vulnerability addressed by MS02-015 is a flaw in the way Internet Explorer 5.01, 5.5, and 6.0 handle cookies. Specifically, the flaw allows some cookies to run arbitrary code on a Web site visitor's system. Microsoft has also released two other bulletins, MS02-016 (blocking Group Policy) and MS02-017 (unchecked buffer in multiple UNC provider), which affect Windows NT and Windows 2000 workstation and server installations as well as XP Professional. Risk levels MS02-015-Critical: This is a cumulative patch for IE 5.01, 5.5, and 6.0, so the threat levels for the various vulnerabilities vary, but at least two of them are rated critical by Microsoft. Taken together, the other fixes are rated critical for Internet and intranet servers, as well as client systems. In particular, the cookie vulnerability, CAN-2002-0078, bypasses security zone restrictions allowing embedded HTML code to run with local computer zone privileges. Since this threat allows attackers to insert their own code, it is potentially much more dangerous than the CodeBase threat, which can run only executable files that are already on the system and can't even pass any parameters to the programs. At present, the most dangerous action known to be possible using the CodeBase attack is to simply shut down a target system. MS02-016-Moderate: Group Policy is a Windows 2000 utility that allows administrators to specify most of the options that are available to all users on the network. This vulnerability allows an attacker to lock the Group Policy utility by opening it under "exclusive-read." At that point, the Group Policy would no longer be applied to any new logins, either by the attacker or by anyone else, as long as it remains open. MS02-017-Low to moderate: Exploiting this vulnerability would allow an attacker to gain higher privileges on the system. Applicability MS02-015: This applies to IE 5.01 through 6.0. Microsoft has backtracked on its support policy limitations and included patches for IE 5.01 (for NT 4) in this update and says it will now continue to support IE 5.01 patches through June 2002. Microsoft says this change is due to "customer feedback" (i.e., complaints). MS02-016: This applies to Windows 2000 Server, Advanced Server, and Datacenter Server. MS02-017: This applies to XP Professional and all versions of NT 4 and Windows 2000. Mitigating factors MS02-015: The cookie threat has just a couple of mitigating factors. First, the user must visit a Web site or open an e-mail containing the infection and then revisit the site to trigger the planted executable. Second, local users who have restricted privileges aren't subject to the threat. The CodeBase vulnerability has a number of mitigating factors, as detailed in my earlier article. The most important are that the attacker can run only executables that are already on the site and can't pass any parameters to those programs. MS02-016: The most important mitigating factor is that the administrator can determine who locked the Group Policy. Since this vulnerability can be exploited only by someone with a valid username and password, the fact that the username can be identified makes this a relatively unattractive way to attack a system. Also, this attack will only temporarily block the application of group policies. It won't allow the attacker to alter any of the established policies permanently. MS02-017: This can be exploited only by someone who can log on to the system interactively-and best practices recommendations say that users shouldn't be allowed interactive logon to critical applications. On Windows 2000 systems, the attacker will also need to know the location of the buffer in memory, and this information isn't available from Win2K. Fix In all instances, fixes can be applied with the supplied patches from the various Microsoft Security Bulletins, MS02-015, MS02-016, and MS02-017. The only exception is the MS02-016 vulnerability for the Windows 2000 Datacenter Server. The patch for this one is hardware-specific and must be obtained from the hardware OEM. Final word One of the most significant side notes in MS02-015 is the indication that customer complaints have caused Microsoft to extend support for an older application (IE 5.01). Since NT 4 is still in widespread use, especially in the government, extending support for even a few months can make a big difference to managers with tight upgrade budgets. Of additional interest is the fact that MS02-015 includes a patch for the CodeBase vulnerability, which some security specialists say Microsoft has known about for a long time but has only now addressed.
Have your say instantly in the Tech Update forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

12 minutes ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

4 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

5 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

5 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

6 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

6 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

7 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

7 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

7 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

7 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

8 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

11 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

12 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

12 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

13 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

14 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

15 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

24 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility