KAZEY JOURNAL

7/22/2004

Patching the Privilege Escalation Vulnerability

Filed under: security — kayode muyibi @ 1:22 pm
Patch MS04-19, which addresses the privilege escalation
vulnerability described below, is one of many patches currently in St.
Bernard Software’s comprehensive UpdateEXPERT® patch metadatabase.
As a busy IT professional, do you really have time to inventory,
research, test, validate, and report on each patch? Let UpdateEXPERT
Patch Management work for you. All the steps are automated and our
scalable architecture works on large and small enterprises alike.
UpdateEXPERT always checks for patch interdependencies and includes
custom deployment options. Find out why UpdateEXPERT was named a
TechTarget 2004 Product of the Year. Download a Free 15-day Live Trial
Today!

http://list.winnetmag.com/cgi-bin3/DM/y/egnr0IFWcR0CBw0BJ4l0Av

========================================================

Security Alert, July 21, 2004

Privilege-Escalation Vulnerability in Microsoft Utility Manager for
Windows

Cesar Cerrudo of Application Security, Inc., discovered that a
privilege-elevation vulnerability exists in the way in which Utility
Manager launches applications. A logged-on user could force Utility
Manager to start an application with system privileges, then take
complete control of the system. Microsoft has released bulletin
MS04-019, “Vulnerability in Utility Manager Could Allow Code Execution
(842526),” to address this vulnerability and recommends that affected
users apply the appropriate patch listed in the bulletin. http://secadministrator.com/articles/index.cfm?articleid=43270

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment

Powered by WordPress