Windows NT 4.0 Terminal Server Edition Winsock Mutex Vulnerability Patch

Software Screenshot:
Windows NT 4.0 Terminal Server Edition Winsock Mutex Vulnerability Patch
Software Details:
Version: MS01-003
Upload Date: 6 Dec 15
Developer: Microsoft
Distribution Type: Freeware
Downloads: 33
Size: 143 Kb

Rating: 1.0/5 (Total Votes: 1)

This patch eliminates a security vulnerability in Windows NT 4.0. The vulnerability could allow a malicious user to run a special program to disable an affected computer's network functionality. Like all other objects under Windows NT 4.0, mutexes--synchronization objects that govern access to resources--have permissions associated with them, that govern how they can be accessed. However, a particular mutex used to govern access to a networking resource has inappropriately loose permissions. This could enable an attacker who had the ability to run code on a local machine to monopolize the mutex, thereby preventing any other processes from using the resource that it controlled. This would have the effect of preventing the machine from participating in the network.

The attacker would require interactive logon access to the affected machine. This significantly limits the scope of the vulnerability because, if normal security recommendations have been followed, unprivileged users will not be granted interactive logon rights to critical machines like servers. Unprivileged users typically are granted interactive logon rights to workstations and terminal servers. However, a workstation would not be a tempting target for an attacker, because he could only use this vulnerability to deny service to himself. The machines most likely to be affected would be terminal servers.

Requirements:

Windows NT

Supported Operation Systems

Similar Software

Other Software of Developer Microsoft

Comments to Windows NT 4.0 Terminal Server Edition Winsock Mutex Vulnerability Patch

Comments not found
Add Comment
Turn on images!