News

Microsoft Fixes NT 4.0 Bug

Microsoft released a patch to eliminate a security vulnerability in Windows NT 4.0. The vulnerability could allow a user logged onto an NT 4.0 machine from the keyboard to become an administrator on the machine.

LPC Ports is a facility that allows LPC calls on a machine. One of the functions in the LPC Ports API set enables, by design, a server thread to impersonate a client thread on the same machine. A flaw in the validation portion of the function would allow a malicious user to create both the server and client threads and manipulate the impersonation request to allow it to run in the context of any desired user on the local machine, including the System itself.

The primary risk is that a malicious user could gain additional privileges on the local machine. However, it could also be used to cause audit logs to indicate that certain actions were taken by another user.

All flavors of Windows NT 4.0 are affected by the vulnerability. The patch for Windows NT 4.0 Workstation, Windows NT 4.0 Server, and Windows NT 4.0 Server, Enterprise Edition are available for Intel platform machines at http://www.microsoft.com/downloads/release.asp?ReleaseID=17382 and for Alpha machines at http://www.microsoft.com/downloads/release.asp?ReleaseID=17383. A patch for Windows NT 4.0 Server, Terminal Server Edition will be available soon. -- Isaac Slepner

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Starts Countdown to Dynamics GP End-of-Support

    Dynamics GP, Microsoft's venerable enterprise resource planning (ERP) solution for midsized businesses, is set to lose support in four years.

  • Image of a futuristic maze

    The 2024 Microsoft Product Roadmap

    Everything Microsoft partners and IT pros need to know about major Microsoft product milestones this year.

  • Windows Recall Preview Starts Rolling Out with Windows 11 24H2

    Microsoft on Tuesday began rolling out Windows 11 version 24H2, describing the update as a "full OS swap that contains new foundational elements required to deliver transformational Al experiences and exceptional performance."

  • An image of planes flying around a globe

    2024 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.