MS warns of hole in Windows 2000

Flaw allows a user to gain new privileges on a computer network.

Security experts have discovered a fault in Microsoft's flagship operating system Windows 2000 that could allow a malicious user to hijack a system and perform any operation they wish. The flaw with the Windows 2000 Event Viewer, which logs details of activity on a Windows 2000 system, could allow an ordinary user to carry out privileged system commands, Microsoft has confirmed.

Exploiting the vulnerability, a malicious user could write a specially formatted event to the Event Viewer, which would execute unauthorised code when the log is next viewed. If the next user to view the log is an administrator, super-user commands can be carried out.

The one mitigating aspect of the vulnerability is that the malicious user must already have access to a target computer system.

"It is not as significant as a wide-ranging vulnerability that could be exploited remotely," said Ian Peacock, security consultant with Swedish computer security firm Defcom. "But companies definitely need to patch this."

Microsoft has issued an alert and a patch for the problem available at: http://www.microsoft.com/technet/security/bulletin/MS01-013.asp

Microsoft said that the affected systems are Windows 2000 Professional, Windows 2000 Server, Windows 2000 Advanced Server and Windows 2000 Datacenter Server.

This is just the latest security flaw to affect Microsoft. A major vulnerability was recently discovered with the software giant's leading email client Outlook.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue 12 days without ADSL: A local loop eulogy
    When your broadband speeds are limited to 38Kbps it's not hard to join the ranks of people demanding the NBN already. Telstra's copper network is a renovator's delight.
  • Array An abridged history of the Aussie internet
    Journalist Glenda Korporaal has written "20 years of the internet in Australia" to commemorate two decades of AARNET. On this week's Twisted Wire I talk to Glenda and Chris Hancock, the CEO of AARNET.
  • Array G'Day USA: Aussie start-ups head to America
    The G'Day USA: Australia Week campaign today announced the finalists for the Innovation Shoot Out event, which will see eight Australian technology start-ups travel to San Francisco in January 2010 to demonstrate the commercial viability of their products in the US.
  • More blogs »

Tags

Back to top

Featured