Microsoft upgrades threat rating on server flaw

Microsoft has been forced to upgrade its latest security advisory after a problem it originally classified as a Denial of Service (DoS) vulnerability was found to be much more serious by security researchers.

The advisory was originally released last Wednesday, and described the vulnerability that affected the Windows Media Services component of the Microsoft IIS Web-server as moderate.

It was re-released on Friday. It upgraded the threat rating to "Important".

"On May 28th, Microsoft released the initial version of this bulletin, rating the severity of the vulnerability as Moderate. Subsequent to that release we have determined that the actions an attacker could take as a result of exploiting this vulnerability could include the ability to execute arbitrary code," it said. "As a result, Microsoft has reissued this bulletin and changed the severity rating to Important".

Although the security advisory was updated, the original patch for the software remains unchanged.

"The original patch corrects the vulnerability and is not being re-released," the updated advisory says.

This came at a bad time for Microsoft, which was forced to pull a patch offline after it caused serious problems for Windows XP users who installed it.

Like this article? Click below to send it to your mobile for free!

Talkback 2 comments

  1. The only bad time I've ever seen for micro$oft was when they have been forced to admit the truth. Such as on the witness stand when billy gates testified to the fact that the windoze os as published by m$ could never be secure due to the architecture of Anonymous -- 03/06/03

    The only bad time I've ever seen for micro$oft was when they have been forced to admit the truth. Such as on the witness stand when billy gates testified to the fact that the windoze os as published by m$ could never be secure due to the architecture of the underlying kernel messaging system.

    Why is anyone who installs an m$ patch surprised that it breaks other "features" of said operating system? That is a known fact also.

    For those of you who use windoze products, you get what you pay (an outrageous price) for: poorly written software without any guarentee of operating as defined in the eula...

    Pete

  2. MS issues patches, retracts them, then more patches to cover patches already retracted. No wonder a "patch machine" mediates the hideously complex process of fixing its product. Even that machine breaks down, apparen Anonymous -- 03/06/03

    MS issues patches, retracts them, then
    more patches to cover patches already
    retracted. No wonder a "patch machine"
    mediates the hideously complex process
    of fixing its product. Even that machine
    breaks down, apparently, for one reason--
    it needs patches.

    Not only are MS products not exemplars of
    secure engineering, they rarely are models
    for any kind of engineering, according to
    the criticisms currently posted around the
    web.

Add your opinion


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured