Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01)
Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01) Ranking & Summary
Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01) description
Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01) is developed to fix the vunerability for Network Dynamic Data Exchange, a technology that enables applications on different Windows computers to dynamically share data. It is affected via communications channels called trusted shares,which is managed by a service called the Network DDE Agent. In Windows 2000, the Network DDE Agent runs using the Local System security context and processes all requests using this context, rather than that of the user. This would give an attacker an opportunity to cause the Network DDE Agent to run code of her choice in Local System context, as a means of gaining complete control over the local machine.
By design, processes on the local machine can levy requests upon the Network DDE Agent, including ones that indicate what application should be run in conjunction with a particular trusted share. However, a vulnerability exists because,
Microsoft recommends that customers using Windows 2000 workstations or who allow unprivileged users to run code on Windows 2000 servers apply the patch immediately. In addition, customers operating Windows 2000 Web servers should consider applying the patch to those machines as well, as a precautionary measure.
Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01) Screenshot
Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01) Keywords
Bookmark Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01)
Windows 2000 Network DDE Vulnerability Patch MS01-007 (2/9/01) Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- SQL Server Documentation Tool 6.7
- Native POP3 Connector 2.4.5
- IQWF Server Professional Version Personal Edition
- SQL Server Backup 7.4.2.5926
- Microsoft Commerce Server 2000 Service Pack 1 Symb Update
- Microsoft Exchange 2000 Enterprise Edition Informa
- Microsoft Exchange 2000 Conferencing Server Setup
- Microsoft Windows 2000 Advanced Server Update: Hig
- Windows XP RPC Interface Buffer Overrun Security Vulnerability Patch 823980
- Microsoft Excel 2002 for Windows Macro Modification Security Vulnerability Patch MS01-050
- Windows 2000 Server 1.0
- Microsoft VM File Reading Vulnerability patch 1
- Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1
- Microsoft Clip Art Buffer Overrun Vulnerability Patch 1
- Microsoft IIS Malformed Extension Data in URL Vulnerability patch MS00-030
- Microsoft Internet Explorer HTML Help File Code Execution Vulnerability patch 6-8-2000
- Internet Explorer 5.5 Scriptlet Rendering Vulnerability Patch
- Microsoft SQL Server 2000 Service Pack 1 Analysis Services Components 1.0
- Microsoft Access 2000 and SQL Server 2000 Readiness Update 12-21-00
- Personal Web Server File Access Vulnerability Patch (FrontPage 98)
- Windows 2000 Datacenter Server 1.0
- Microsoft SQL Server 2000 Service Pack 1 Database Components 1.0
- Access to SQL2000 3.13
- IE5.5 SP1 File Upload via Form Vulnerability Patch MS00-093