Click here to get back home

MS08-002 Vulnerability in LSASS Could Allow Local Elevation of Privilege (943485)

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
MS08-002 Vulnerability in LSASS Could Allow Local Elevation of Privilege (943485) MNews 02-01-2008
Posted by MNews on February 1, 2008, 1:22 pm
Please log in for more thread options
Dumb question, but the bulletin states it affects windows server 2003 sp1
and sp2. What about 2003 server no SP?
We have a few where SP1 broke a critical app and the vendor advised us not
to apply SP1. This server is not exposed to the public internet. and
everything works swell without the SP.

Regards

Carl



Posted by Alun Jones on February 1, 2008, 1:56 pm
Please log in for more thread options
> Dumb question, but the bulletin states it affects windows server 2003 sp1
> and sp2. What about 2003 server no SP?

This is what "not supported" means. As of April 10 last year, Server 2003
RTM was retired. http://support.microsoft.com/gp/lifesupsps#Servers - unless
you pay for Extended support (which is around $4000 per incident, at least
at the time of the DST changes), Microsoft isn't going to spend the time to
see whether or not this affects an unsupported version of the OS.

> We have a few where SP1 broke a critical app and the vendor advised us not
> to apply SP1. This server is not exposed to the public internet. and
> everything works swell without the SP.

By now your vendor should have provided you with a fix, because right now
they are suggesting that you run on a version of Windows that isn't
supported by Microsoft.

Alun.
~~~~



Posted by MNews on February 1, 2008, 2:10 pm
Please log in for more thread options
Thanks
Actually we just contacted them and they tell us the application with the
latest patches will work with SP2.
So We will just attempt a weekend upgrade to SP2 on the affected system-
after a full IDR backup.



>> Dumb question, but the bulletin states it affects windows server 2003 sp1
>> and sp2. What about 2003 server no SP?
>
> This is what "not supported" means. As of April 10 last year, Server 2003
> unless you pay for Extended support (which is around $4000 per incident,
> at least at the time of the DST changes), Microsoft isn't going to spend
> the time to see whether or not this affects an unsupported version of the
> OS.
>
>> We have a few where SP1 broke a critical app and the vendor advised us
>> not to apply SP1. This server is not exposed to the public internet.
>> and everything works swell without the SP.
>
> By now your vendor should have provided you with a fix, because right now
> they are suggesting that you run on a version of Windows that isn't
> supported by Microsoft.
>
> Alun.
> ~~~~
>



Posted by Mr Crowley on February 1, 2008, 8:42 pm
Please log in for more thread options
Alun
Curious, the list of affected OS includes windows 2000 for that bulletin.
That looked like it was retired.

MC

>> Dumb question, but the bulletin states it affects windows server 2003 sp1
>> and sp2. What about 2003 server no SP?
>
> This is what "not supported" means. As of April 10 last year, Server 2003
> unless you pay for Extended support (which is around $4000 per incident,
> at least at the time of the DST changes), Microsoft isn't going to spend
> the time to see whether or not this affects an unsupported version of the
> OS.
>
>> We have a few where SP1 broke a critical app and the vendor advised us
>> not to apply SP1. This server is not exposed to the public internet.
>> and everything works swell without the SP.
>
> By now your vendor should have provided you with a fix, because right now
> they are suggesting that you run on a version of Windows that isn't
> supported by Microsoft.
>
> Alun.
> ~~~~
>



Posted by Alun Jones on February 4, 2008, 12:51 pm
Please log in for more thread options
Yay - you get a freebie. If a supported piece of software is absent from the
Affected Software list, it is because the current belief is that the
software is not vulnerable (occasionally, there are oversights - Small
Business Server and Windows Home Server appear to be most frequently
affected by these oversights), but if an unsupported piece of software is
absent from the list, well, that's just normal - unsupported software is not
generally inspected against new vulnerability reports.

Alun.
~~~~

> Alun
> Curious, the list of affected OS includes windows 2000 for that bulletin.
> That looked like it was retired.
>
> MC
>
>>> Dumb question, but the bulletin states it affects windows server 2003
>>> sp1 and sp2. What about 2003 server no SP?
>>
>> This is what "not supported" means. As of April 10 last year, Server 2003
>> unless you pay for Extended support (which is around $4000 per incident,
>> at least at the time of the DST changes), Microsoft isn't going to spend
>> the time to see whether or not this affects an unsupported version of the
>> OS.
>>
>>> We have a few where SP1 broke a critical app and the vendor advised us
>>> not to apply SP1. This server is not exposed to the public internet.
>>> and everything works swell without the SP.
>>
>> By now your vendor should have provided you with a fix, because right now
>> they are suggesting that you run on a version of Windows that isn't
>> supported by Microsoft.
>>
>> Alun.
>> ~~~~
>>
>
>



Similar ThreadsPosted
The privilege to start a Windows service June 13, 2006, 6:37 am
System Logs: Remote Access for Low-Privilege Account October 22, 2006, 12:02 pm
Finding Which Application Requires Specific User Privilege? December 26, 2006, 3:17 am
IIS vulnerability (MS06-034) July 12, 2006, 1:46 pm
ISAPI Filter Vulnerability November 7, 2006, 11:15 pm
Is NT4 affected by the new MS05-039 Plug-n-Play Vulnerability? August 15, 2005, 9:33 am
Windows Media Player vulnerability in Win2K3 Server with SP2 October 25, 2007, 2:06 pm
Remote Desktop Protocol Server Private Key Disclosure Vulnerability March 30, 2008, 9:34 am
LSASS errors July 22, 2005, 10:57 am
Lsass.exe error 128 September 4, 2005, 5:18 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap