(Apparently not need when firewalls are used, and not needed 
when the "Web Client" Service is disabled and it can be 
disabled on typical PC's.  Again, this one below also states 
"Local system" and that does not appear to be the case).


TITLE:
Microsoft Windows Web Client Service Vulnerability

SECUNIA ADVISORY ID:
SA18857

VERIFY ADVISORY:
http://secunia.com/advisories/18857/

CRITICAL:
Less critical

IMPACT:
Privilege escalation

WHERE:
Local system

OPERATING SYSTEM:
Microsoft Windows XP Professional
http://secunia.com/product/22/
Microsoft Windows XP Home Edition
http://secunia.com/product/16/
Microsoft Windows Server 2003 Web Edition
http://secunia.com/product/1176/
Microsoft Windows Server 2003 Standard Edition
http://secunia.com/product/1173/
Microsoft Windows Server 2003 Enterprise Edition
http://secunia.com/product/1174/
Microsoft Windows Server 2003 Datacenter Edition
http://secunia.com/product/1175/

DESCRIPTION:
A vulnerability has been reported in Microsoft Windows, which 
can be
exploited by malicious, local users to gain escalated 
privileges.

The vulnerability is caused due to a boundary error in Web 
Client
Service the handling of WebDAV messages.

SOLUTION:
Apply patches:

Microsoft Windows XP SP1 / Microsoft Windows XP SP2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=62535040-5204-4469-B0BF-EAE14567C2D5

Microsoft Windows XP Professional x64 Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9734F634-6869-434F-AAF0-47B70F84D178

Microsoft Windows Server 2003 and Microsoft Windows Server 2003 
SP1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=FA073183-0C83-4F1C-BE46-A2EE8A1A1440

Microsoft Windows Server 2003 (Itanium) / Microsoft Windows 
Server
2003 SP1 (Itanium):
http://www.microsoft.com/downloads/details.aspx?FamilyId=E186E149-208A-4035-A0FC-E1CBDE4E6FEF

Microsoft Windows Server 2003 x64 Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=E2F5413A-0B77-4C18-9BAB-E2470D3D3F4E

ORIGINAL ADVISORY:
MS06-008 (KB911927):
http://www.microsoft.com/technet/security/Bulletin/MS06-008.mspx
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to