NTA Monitor

Latest News

New version of network scanning tool arp-scan released

15th March 2011 A new version of a respected and popular network scanning tool has been released. Read More

Tests show rise in number of vulnerabilities affecting web applications with SQL Injection and XSS most common flaws

1st March 2011 SQL injection and cross-site scripting (XSS) were the most common flaws found in web applications in 2010 according to results from tests carried out by NTA Monitor. Read More

Assess risk to manage effects of budget cuts

9th February 2011 Signs of economic recovery may be appearing in some industries, but for most organisations - particularly in the public sector - budget cuts and cost savings are here to stay for the foreseeable future. Read More

"Basic security threats not changed in 15 years"

1st February 2011 There may have been significant technological advances to the hardware and software organisations use, but according to Roy Hills, who co-founded NTA Monitor in 1996, the basic security threats have not changed in the last 15 years. Read More
Date: 30th September 2005
Risk: Medium

Title: Cumulative Security Update for Internet Explorer (896727) MS05-038

Summary: Vulnerabilities exist in Internet Explorer, the most severe of these could allow an attacker to take complete control of an affected system.

Vulnerability: Remote Code Execution

Rating: High

Affected Software: Win XP SP1SP2, XP Pro x64, Server 2K3 and Server 2K3 SP1, Server 2K3 for Itanium Server & 2K3 SP1 for Itanium, Server 2K3 x64, Win98, Win98 SE, Win ME

Affected Components: IE 5.01 SP4 on Win2K SP4, IE6 SP1 on Win2K SP4 or on Win XP SP1, IE6 for Win XP SP2, IE6 for Win Server 2K3 and Win Server 2K3 SP1, IE6 for Win Server 2K3 for Itanium and SP1, IE6 for Win Server 2K3 x64, IE6 for Win XP Pro x64, IE 5.5 SP2 on Win ME, IE6 SP1 on Win98, on Win98 SE, or on Win ME

Title: Vulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588) MS05-039

Summary: A remote code execution vulnerability exists in Plug and Play (PnP) that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.

Vulnerability: Remote Code Execution and Local Elevation of Privilege

Rating: High

Affected Software: Win2K SP4, Win XP SP1 and Win XP SP2, Win XP Pro x64, Win Server 2K3 and Win Server 2K3 SP1, Win Server 2K3 for Itanium and Win Server 2K3 SP1 for Itanium, Win Server 2K3 x64

Non-Affected Software: Win98, Win98 SE, and Win ME

Title: Vulnerability in Print Spooler Service Could Allow Remote Code Execution (896423) MS05-043

Summary: Vulnerability exists in the Print Spooler service that could allow remote code execution.

Vulnerability: Remote Code Execution

Rating: High

Affected Software: Win2L SP4, Win XP SP1 and Win XP SP2, Win Server 2K3, Win Server 2K3 for Itanium

Non-Affected Software: Win XP Pro x64, Win Server 2K3 SP1, Win Server 2K3 SP1 for Itanium, Win Server 2K3 x64, Win 98, Win 98 SE, and Win ME

Title: Vulnerability in Telephony Service Could Allow Remote Code Execution (893756) MS05-040

Summary: A vulnerability exits in the Telephony Application Programming Interface (TAPI) service that could allow remote code execution.

Vulnerability: Remote Code Execution

Rating: Medium

Affected Software: Win 2K SP4, Win XP SP1 and Win XP SP2, Win XP Pro x64, Win Server 2K3 and Windows Server 2K3 SP1, Win Server 2K3 for Itanium and Win Server 2K3 with SP1 for Itanium, Win Server 2K3 x64, Win98, Win98 SE, and Win ME

Title: Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (899591) MS05-041

Summary: A vulnerability in the Remote Desktop Protocol (RDP) exists that could allow an attacker to cause a system to stop responding.

Vulnerability: Denial of Service

Rating: Medium

Affected Software: Win 2K Server SP4, Win XP SP1 and Win XP SP2, Win XP Pro x64, Win Server 2K3 and Win Server 2K3 SP1, Win Server 2K3 for Itanium and Win Server 2K3 with SP1 for Itanium, Win Server 2K3 x64

Non-Affected Software: Win 2K Pro SP4, Win98, Win98 SE, and Win ME

Title: Vulnerabilities in Kerberos Could Allow Denial of Service, Information Disclosure, and Spoofing (899587) MS05-042

Summary: This update resolves two newly discovered vulnerabilities. The most severe of these vulnerabilities could allow denial of service.

Vulnerability: Denial of Service, Information Disclosure, and Spoofing.

Rating: Medium

Affected Software: Win2K SP4, Win XP SP1 and Win XP SP2, Win XP Pro x64, Win Server 2K3 and Win Server 2K3 SP1, Win Server 2K3 for Itanium and Win Server 2K3 with SP1 for Itanium, Win Server 2K3 x64

Non-Affected Software: Win98, Win98 SE, and Win ME

References