MS00-070: Patch for Numerous Vulnerabilities in the LPC Port System Calls
This article was previously published under Q266433 On This PageSYMPTOMS Microsoft has released a patch that addresses a range of
vulnerabilities in local procedure call (LPC) functionality and LPC ports.
These vulnerabilities include:
RESOLUTIONTo resolve this problem, obtain the latest service
pack for Windows 2000. For additional information, click the following article
number to view the article in the Microsoft Knowledge Base: 260910 (http://support.microsoft.com/kb/260910/EN-US/) How to Obtain the Latest Windows 2000 Service Pack
Windows 2000The following files are available for download from the Microsoft Download Center: English Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/en-us/q266433_w2k_sp2_x86_en.exe) Arabic Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/ar/q266433_w2k_sp2_x86_ar.exe) Chinese (Simplified) Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/cn/q266433_w2k_sp2_x86_cn.exe) Chinese (Traditional) Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/tw/q266433_w2k_sp2_x86_tw.exe) Czech Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/cs/q266433_w2k_sp2_x86_cs.exe) Danish Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/da/q266433_w2k_sp2_x86_da.exe) Dutch Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/nl/q266433_w2k_sp2_x86_nl.exe) Finnish Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/fi/q266433_w2k_sp2_x86_fi.exe) French Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/fr/q266433_w2k_sp2_x86_fr.exe) German Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/de/q266433_w2k_sp2_x86_de.exe) Hebrew Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/he/q266433_w2k_sp2_x86_he.exe) Hungarian Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/hu/q266433_w2k_sp2_x86_hu.exe) Italian Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/it/q266433_w2k_sp2_x86_it.exe) Japanese Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/ja/q266433_w2k_sp2_x86_ja.exe) Japanese NEC Language Version (http://download.microsoft.com/download/win2000platform/patchnec/q266433/nt5/ja/q266433_w2k_sp2_nec98_ja.exe) Korean Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/ko/q266433_w2k_sp2_x86_ko.exe) Norwegian Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/no/q266433_w2k_sp2_x86_no.exe) Polish Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/pl/q266433_w2k_sp2_x86_pl.exe) Portuguese (Brazilian) Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/pt-br/q266433_w2k_sp2_x86_br.exe) Portuguese Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/pt/q266433_w2k_sp2_x86_pt.exe) Russian Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/ru/q266433_w2k_sp2_x86_ru.exe) Spanish Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/es/q266433_w2k_sp2_x86_es.exe) Swedish Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/sv/q266433_w2k_sp2_x86_sv.exe) Turkish Language Version (http://download.microsoft.com/download/win2000platform/patch/q266433/nt5/tr/q266433_w2k_sp2_x86_tr.exe)119591 (http://support.microsoft.com/kb/119591/EN-US/) How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
After applying the hotfix, the Windows 2000 System
properties show the system as "Service Pack 1, RC 1.1." This version stamp does
not cause any problems. It is simply the version that was coded into the patch.
The English-language version of this fix should have the
following file attributes or later: Date Time Version Size File name ------------------------------------------------------ 7/6/00 1:46pm 5.0.2195.2099 1,659,328 Ntoskrnl.exe 7/6/00 1:46pm 5.0.2195.2099 1,681,536 Ntkrnlmp.exeNOTE: The Ntkrnlmp.exe file is used only on computers with multiple processors. Windows NT 4.0To resolve this problem, obtain the individual package referenced below or obtain the Windows NT 4.0 Security Rollup Package. For additional information on the SRP, click the article number below to view the article in the Microsoft Knowledge Base:299444 (http://support.microsoft.com/kb/299444/EN-US/) Post-Windows NT 4.0 Service Pack 6a Security Rollup Package (SRP)
Download 266433i.exe now (http://www.microsoft.com/Downloads/details.aspx?displaylang=en&FamilyID=F0521C62-34ED-4A35-8EE8-27FA09C37B94)Date Time Version Size File name ------------------------------------------------------ 7/6/00 5:19pm 4.0.1381.7080 934,720 Ntoskrnl.exe 7/6/00 5:19pm 4.0.1381.7080 955,200 Ntkrnlmp.exeNOTE: The Ntkrnlmp.exe file is used only on computers with multiple processors. Windows NT Server 4.0, Terminal Server EditionTo resolve this problem, either obtain the hotfix referenced in this section or the Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (SRP). For more information about the SRP, click the following article number to view the article in the Microsoft Knowledge Base:317636 (http://support.microsoft.com/kb/317636/)
Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package
A supported hotfix is now available from Microsoft, but it is only intended to
correct the problem that this article describes. Apply it only to systems that
you determine are at risk of attack. Evaluate the computer's physical
accessibility, network and Internet connectivity, and other factors to
determine the degree of risk to the computer. See the associated
Microsoft
Security Bulletin (http://www.microsoft.com/technet/security/bulletin/MS00-070.mspx) to help determine the degree of risk. This hotfix
may receive additional testing. If the computer is sufficiently at risk, we
recommend that you apply this hotfix now. To resolve this problem immediately, download the hotfix by following the instructions later in this article or contact Microsoft Product Support Services to obtain the hotfix. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site: http://support.microsoft.com/contactus/?ws=support (http://support.microsoft.com/contactus/?ws=support) Note In special cases, charges that are ordinarily incurred for
support calls may be canceled, if a Microsoft Support Professional determines
that a specific update will resolve your problem. The usual support costs will
apply to additional support questions and issues that do not qualify for the
specific update in question.
The
following file is available for download from the Microsoft Download
Center: Download Q266433i.exe now (http://www.microsoft.com/Downloads/details.aspx?displaylang=en&FamilyID=F0521C62-34ED-4A35-8EE8-27FA09C37B94)For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591 (http://support.microsoft.com/kb/119591/EN-US/) How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
NOTE: After you apply this patch, the operating system version changes
from Build 1381: Service Pack 6 to Build 1381: Service Pack 6, RC1.6. This change in the displayed version number does not cause any
errors or issues.The English version of this fix should have the following file attributes or later: Date Time Version Size File name ----------------------------------------------------------- 29-Jan-2001 11:46 4.0.1381.33474 1,003,392 Ntkrnlmp.exe 29-Jan-2001 11:39 156,496 Ntldr 29-Jan-2001 11:46 4.0.1381.33474 982,144 Ntoskrnl.exeNOTE: Due to file dependencies, this update requires Windows NT Server 4.0, Terminal Server Edition Service Pack 6. STATUSWindows 2000Microsoft has confirmed that this problem may cause a degree of security vulnerability in Windows 2000. This problem was first corrected in Windows 2000 Service Pack 2.Windows NT 4.0Microsoft has confirmed that this problem may cause a degree of security vulnerability in Windows NT 4.0.Windows NT Server 4.0, Terminal Server EditionMicrosoft has confirmed that this problem may cause a degree of security vulnerability in Windows NT Server 4.0, Terminal Server Edition.MORE INFORMATION For additional information about this issue, view the
following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/MS00-070.mspx (http://www.microsoft.com/technet/security/bulletin/MS00-070.mspx) Frequently asked questions about this vulnerability are available
on the following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/fq00-070.mspx (http://www.microsoft.com/technet/security/bulletin/fq00-070.mspx) APPLIES TO
| Article Translations
|
Back to the top
