Microsoft Netmon Protocol Parsing Vulnerability Patch (Windows 2000)

Software Screenshot:
Microsoft Netmon Protocol Parsing Vulnerability Patch (Windows 2000)
Software Details:
Version: (MS00-083)
Upload Date: 6 Dec 15
Developer: Microsoft
Distribution Type: Freeware
Downloads: 8
Size: 1479 Kb

Rating: nan/5 (Total Votes: 0)

This patch eliminates a security vulnerability in Microsoft Windows 2000 server products and Systems Management Server. The vulnerability could allow a malicious user to gain control of an affected server.

Microsoft ships two versions of Network Monitor (Netmon): a basic version that ships with Windows NT 4.0 and Windows 2000 server products, and a full version that ships as part of Systems Management Server (SMS) 1.2 and 2.0. Both versions include protocol parsers that aid administrators in interpreting and analyzing previously captured network data. However, several of the parsers have unchecked buffers. If a malicious user delivered a specially malformed frame to a server that was monitoring network traffic, and the administrator parsed it using an affected parser, it would have the effect of either causing Netmon to fail or causing code of the malicious user's choice to run on the machine.

Netmon requires administrative privileges to run, but should only be run by local, rather than domain, administrators. If this is done, the vulnerability could be used to gain complete control over the local machine, but could not be used to gain control over a domain. Netmon does not ship on workstation products, so unless SMS had been installed on a workstation, it would not be affected by this vulnerability.

Read the Netmon Protocol Parsing Vulnerability FAQ.

Supported Operation Systems

Similar Software

Other Software of Developer Microsoft

Comments to Microsoft Netmon Protocol Parsing Vulnerability Patch (Windows 2000)

Comments not found
Add Comment
Turn on images!