[ news_security_news ] Vulnerability Discovered In WINS
SecurityProNews Staff Writer
2004-12-01
Insider Reports RSS Feed
A vulnerability has been discovered in the Microsoft Windows Internet Naming Service (WINS).
A WINS server is a Microsoft NetBIOS name server that eliminates the need for broadcast packets to resolve a NetBIOS computer name to an IP address. The vulnerability was discovered in the WINS server replication feature, which allows one or more WINS servers to exchange information with each other about the computers on their respective networks. By default, WINS is installed and running on Microsoft Small Business Server 2000 and on Microsoft Windows Small Business Server 2003. WINS is off by default on all other Microsoft server operating systems.
Organizations that have deployed ISS products or using ISS managed services are preemptively protected against all threats targeting this vulnerability.
Organizations not protected by ISS preemptive solutions should note:
An attacker who successfully exploits this vulnerability could take complete control of an affected system, including installing malicious programs; viewing, changing, or deleting confidential information; or further network compromise.
Affected Infrastructure:
By default, WINS is not installed on:
* Windows NT Server 4.0
* Windows NT Server 4.0 Terminal Server Edition
* Windows 2000 Server
* Windows Server 2003.
By default, WINS is installed and running on:
* Microsoft Small Business Server 2000
* Microsoft Windows Small Business Server 2003
On all versions of Microsoft Small Business Server, the WINS component communication ports are blocked from the Internet and WINS is available only on the local network.
Available Protection:
Microsoft is currently developing a patch for this vulnerability. To mitigate exposure, it is recommended that organizations block TCP port 42 and UDP 42 at the firewall. Organizations that do not need WINS are encouraged to remove it from their systems if it has been installed. WINS is not enabled by default on Microsoft server operating systems with the exception of Small Business Server 2000 and Small Business Server 2003.
About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.
More news_security_news Articles
Insider Reports RSS Feed
|
|