News

RPC Vulnerability Affects NT, W2K, XP

Microsoft on Wednesday warned users of an "important" new vulnerability involving the Remote Procedure Call (RPC) protocol in Windows NT, Windows 2000 and Windows XP that can allow a denial-of-service attack.

While a patch is available for Windows 2000 and Windows XP, Redmond cited architectural issues as preventing the company from creating a patch for Windows NT 4.0. The company provided workaround instructions, instead, for NT customers in the bulletin (www.microsoft.com/technet/security/bulletin/MS03-010.asp).

Microsoft's bulletin said servers on an intranet were the most likely to be vulnerable to the attack. The company went further to suggest that responsible network security practices should prevent the vulnerability from being open on Internet servers. "Best practices recommend blocking all TCP/IP ports that are not actually being used," the bulletin stated. "For this reason, most machines attached to the Internet should have port 135 blocked. RPC over TCP is not intended to be used in hostile environments such as the Internet."

The bulletin is Microsoft's 10th of 2003.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.