Vulnerability Development mailing list archives

RE: CR II - winME? confirmation? (Slightly OT)


From: Mike Duncan <security () randomtask net>
Date: Thu, 9 Aug 2001 15:15:23 -0400 (EDT)

I would like to offer a quote from MS01-033:

"the service would not need to be running in order for an attacker to
exploit the vulnerability."

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
bulletin/MS01-033.asp

Carey 

Yeah ... and you forgot to metion the (almost) first line on that same
page...

"Who should read this bulletin: System administrators of web servers using
Microsoft® Windows NT® 4.0 or Windows® 2000."


Mike Duncan
security () randomtask net
http://www.randomtask.net

"This is what happens when parents make 
their kids play with dried up Play-Doh."
                              - Tim Mullen




Current thread: