sábado, abril 24, 2004
Parches de Microsoft para Abril 2004. Basados en Windows.
Microsoft nos alerta de que una de las últimas vulnerabilidades publicadas MS04-11 está siendo usada con una aplicación para provocar la denegación de servicio de los servidores que tienen habilitado el protocolo SSL.
---------------------------------------------------------------------------
Microsoft is aware of code available on the Internet that seeks to exploit vulnerabilities addressed as part of our April 13th security updates. We are investigating the situation to help protect our customers. Specifically, the reports detail exploit code that attempts to use the IIS PCT/SSL vulnerability on servers running Internet Information Services with the Secure Socket Layer authentication enabled. This vulnerability is addressed by bulletin MS04-011. Customers who have deployed MS04-011 are not at risk from this exploit code.
Microsoft considers these reports credible and serious and continues to urge all customers to immediately install the MS4-011 update as well as the other critical updates provided on April 13th. Customers who are still evaluating and testing MS04-011 should immediately implement the workaround steps detailed for the PCT/SSL vulnerability detailed in the MS04-011. In addition, Microsoft has published a knowledge base article KB187498 at http://support.microsoft.com/default.aspx?scid=kb;en-us;187498 which provides additional details on SSL and how to disable PCT without applying MS04-011.
We expect to see additional exploits and proof-of-concept code targeting the April 2004 security bulletin release in coming days and weeks, potentially including worm or virus examples.
-------------------------------------------------------------
Se recomienda que la aplicación del parche de seguridad se haga a la mayor brevedad posible !!!.
Aquí teneis el enlace con todos los parches publicados en Abril.
http://www.microsoft.com/security/security_bulletins/200404_windows.asp
Nota: Me despisto un día y no veas la que se forma ! (Benjamin Mateos ;-))
-----------------------
Carlos Dinapoli
|
---------------------------------------------------------------------------
Microsoft is aware of code available on the Internet that seeks to exploit vulnerabilities addressed as part of our April 13th security updates. We are investigating the situation to help protect our customers. Specifically, the reports detail exploit code that attempts to use the IIS PCT/SSL vulnerability on servers running Internet Information Services with the Secure Socket Layer authentication enabled. This vulnerability is addressed by bulletin MS04-011. Customers who have deployed MS04-011 are not at risk from this exploit code.
Microsoft considers these reports credible and serious and continues to urge all customers to immediately install the MS4-011 update as well as the other critical updates provided on April 13th. Customers who are still evaluating and testing MS04-011 should immediately implement the workaround steps detailed for the PCT/SSL vulnerability detailed in the MS04-011. In addition, Microsoft has published a knowledge base article KB187498 at http://support.microsoft.com/default.aspx?scid=kb;en-us;187498 which provides additional details on SSL and how to disable PCT without applying MS04-011.
We expect to see additional exploits and proof-of-concept code targeting the April 2004 security bulletin release in coming days and weeks, potentially including worm or virus examples.
-------------------------------------------------------------
Se recomienda que la aplicación del parche de seguridad se haga a la mayor brevedad posible !!!.
Aquí teneis el enlace con todos los parches publicados en Abril.
http://www.microsoft.com/security/security_bulletins/200404_windows.asp
Nota: Me despisto un día y no veas la que se forma ! (Benjamin Mateos ;-))
-----------------------
Carlos Dinapoli