vesselescape
IS-IT--Management
Have not seen a discussion of this posted, so thought I would pass it along.
As of January 22, 2003 MS has posted an alert and patch for the MS Locator service running on 2K servers (also NT4). Security level is critical for domain controlers where Locator Service is run by default. Buffer exploit can allow code of choice to be run by attacker. Properly configured firewall should preclude outside exploitation, but why take the chance? Full text of alert, and download here:
As of January 22, 2003 MS has posted an alert and patch for the MS Locator service running on 2K servers (also NT4). Security level is critical for domain controlers where Locator Service is run by default. Buffer exploit can allow code of choice to be run by attacker. Properly configured firewall should preclude outside exploitation, but why take the chance? Full text of alert, and download here: