Linked by Thom Holwerda on Tue 8th Aug 2006 19:20 UTC, submitted by anonymous
Microsoft "Microsoft alerted us this time about 12 vulnerabilities of which nine were rated critical and three important. There are vulnerabilities in the Server service, the DNS service, Outlook Express, PowerPoint, the Microsoft Management Console, Visual Basic for Applications, and more."
Order by: Score:
DNS service?
by Ronald Vos on Tue 8th Aug 2006 22:13 UTC
Ronald Vos
Member since:
2005-07-06

Not the DNS service built into every desktop, but a for-server-systems-only DNS service I hope.

Reply Score: 1

RE: DNS service?
by umccullough on Tue 8th Aug 2006 22:44 UTC in reply to "DNS service?"
umccullough Member since:
2006-01-26

well... here's the description on windows update:

A security issue has been identified in DNS Resolution that could allow an attacker to compromise your Windows-based system and gain control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.

with a link to this page: http://www.microsoft.com/technet/security/bulletin/ms06-041.mspx

So, it's a problem with DNS resolution on the CLIENT SIDE!...

Reply Score: 1

RE[2]: DNS service?
by smitty on Wed 9th Aug 2006 14:38 UTC in reply to "RE: DNS service?"
smitty Member since:
2005-10-13

Which is very bad, but presumably the only computers that could compromise the clients would be the DNS servers, which should be fairly well trusted anyway. Or maybe I'm wrong?

Edited 2006-08-09 14:39

Reply Score: 1

RE[3]: DNS service?
by umccullough on Wed 9th Aug 2006 15:03 UTC in reply to "RE[2]: DNS service?"
umccullough Member since:
2006-01-26

Yes - while anyone could run their own DNS server for their own domain - most DNS queries are facilitated through ISP DNS servers (which then cache the queries on behalf of the clients) - so it would be somewhat difficult to coerce a vulnerable machine to issue a request from a compromised server - unless you already had some control over the vulnerable machine in the first place.

Reply Score: 2