Microsoft Windows Security Bulletin Summary for October, 2003 Print
Issued: October 15, 2003
Version Number: 1.0
An End User version of this advisory is available at:
http://www.microsoft.com/security/security_bulletins/20031015_windows.asp.
Protect your PC: Microsoft has provided information on how you can help protect your PC at the following locations:
End Users can visit
http://www.microsoft.com/protect
IT Professionals can visit
http://www.microsoft.com/technet/security/protect
Patch Management Strategies: The Microsoft Guide to Security Patch Management Web Site provides additional information about Microsoft’s best practice recommendations for applying security patches.
IT Pro Security Zone Community: Learn to improve security and optimize your IT infrastructure, and participate with other IT Pros on security topics:
http://www.microsoft.com/technet/security/community/default.mspx
Microsoft Security Notification Service: To receive automatic e-mail notification whenever Microsoft security bulletins are issued, subscribe to the Microsoft Security Notification Service:
http://www.microsoft.com/technet/security/bulletin/notify.asp
Summary
Included in this advisory are updates for five newly discovered vulnerabilities in Microsoft Windows. These vulnerabilities, broken down by severity are:
Critical
Microsoft Security Bulletin MS03-041 - Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)
Affected Software Microsoft Windows NT Workstation 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
Microsoft Windows 2000, Service Pack 2
Microsoft Windows 2000, Service Pack 3, Service Pack 4
Microsoft Windows XP Gold, Service Pack 1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-bit Edition
Impact Remote Code Execution
Last Revised
Version Number 1.0
Microsoft Security Bulletin MS03-042 - Buffer Overflow in the Windows Troubleshooter ActiveX Control Could Allow Code Execution (826232)
Affected Software Microsoft Windows 2000, Service Pack 2
Microsoft Windows 2000, Service Pack 3, Service Pack 4
Impact Remote Code Execution
Last Revised
Version Number 1.0
Microsoft Security Bulletin MS03-043 - Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
Affected Software Microsoft Windows NT Workstation 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
Microsoft Windows 2000, Service Pack 2
Microsoft Windows 2000, Service Pack 3, Service Pack 4
Microsoft Windows XP Gold, Service Pack 1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-bit Edition
Impact Remote Code Execution
Last Revised
Version Number 1.0
Microsoft Security Bulletin MS03-044: Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (825119)
Affected Software Microsoft Windows Millennium Edition
Microsoft Windows NT Workstation 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
Microsoft Windows 2000, Service Pack 2
Microsoft Windows 2000, Service Pack 3, Service Pack 4
Microsoft Windows XP Gold, Service Pack 1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-bit Edition
Impact Remote Code Execution
Last Revised
Version Number 1.0
Important
Microsoft Security Bulletin MS03-045: Buffer Overrun in the ListBox and in the ComboBox Control Could Allow Code Execution (824141)
Affected Software Microsoft Windows NT Workstation 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
Microsoft Windows 2000, Service Pack 2
Microsoft Windows 2000 Service Pack 3, Service Pack 4
Microsoft Windows XP Gold, Service Pack 1
Microsoft Windows XP 64 bit Edition
Microsoft Windows XP 64 bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64 bit Edition
Impact Local Elevation of Privilege
Last Revised
Version Number 1.0