Microsoft issues server vulnerability warning

Two vulnerabilities have been found in Microsoft's Biztalk server software, the most serious of which could allow an attacker to fully compromise a targeted Biztalk server.

Microsoft has release an advisory that details the scope of the vulnerabilities, which points out the severity of the more serious 'buffer overflow' glitch.

"[The vulnerability] could provide the attacker with the ability to take any desired action on the machine, such as adding, deleting, or modifying data on the system, and creating or deleting user accounts," it says.

Despite the seriousness of the vulnerabilities, Microsoft has not recommended the immediate application of a software patch that eradicates the security flaws, and has rated the issue as important, but not critical.

"Systems administrators using Microsoft BizTalk should consider applying the patch," the advisory says.

The less serious glitch is a 'SQL injection' vulnerability that may allow an attacker to execute malicious SQL statements.

That problem has been rated as moderate. SQL injection vulnerabilities can lead to database statements being executed that may lead to loss and modification of data.

The problems were found by security researcher Cesar Cerrudo, who reported the problems to Microsoft and worked with them to produce a fix.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured