Windows 2000 Network DDE Vulnerability Patch

Software Screenshot:
Windows 2000 Network DDE Vulnerability Patch
Software Details:
Version: MS01-007 (2/9/01)
Upload Date: 6 Dec 15
Developer: Microsoft
Distribution Type: Freeware
Downloads: 12
Size: 287 Kb

Rating: 3.0/5 (Total Votes: 2)

Network Dynamic Data Exchange (DDE) is a technology that enables applications on different Windows computers to dynamically share data. This sharing is effected via communications channels called trusted shares, which are managed by a service called the Network DDE Agent. By design, processes on the local machine can levy requests upon the Network DDE Agent, including ones that indicate what application should be run in conjunction with a particular trusted share. However, a vulnerability exists because, in Windows 2000, the Network DDE Agent runs using the Local System security context and processes all requests using this context, rather than that of the user. This would give an attacker an opportunity to cause the Network DDE Agent to run code of her choice in Local System context, as a means of gaining complete control over the local machine.

Microsoft recommends that customers using Windows 2000 workstations or who allow unprivileged users to run code on Windows 2000 servers apply the patch immediately. In addition, customers operating Windows 2000 Web servers should consider applying the patch to those machines as well, as a precautionary measure.

Requirements:

Windows 2000 Professional/Server/Advanced Server

Supported Operation Systems

Similar Software

Other Software of Developer Microsoft

Comments to Windows 2000 Network DDE Vulnerability Patch

Comments not found
Add Comment
Turn on images!