QuestionQ707

Endpoint Attack and Pivoting

A newly disclosed buffer-overflow vulnerability affecting the Remote Procedure Call (RPC) mechanism in all versions of Windows has been announced, and exploit code is already available on the Internet. A fix is available. As the administrator of a Windows 2003 Server system, you want to keep the exploit from compromising the system. Which of the following options are available to you?

  • A Set the "noexec_user_stack" and "noexec_user_stack_log" dword values to "1" in the registry
  • B Install the system kernel module from openwall.com
  • C Turn on Unknown Binary Execution Prevention (UBEP) for essential Windows services
  • D Install the latest OS and application patches from Microsoft
Explanation

Microsoft Security Bulletin MS03-026 identifies Windows Server 2003 as affected by the RPC/DCOM buffer-overrun vulnerability and recommends that administrators apply the security patch immediately. Installing the latest Microsoft operating-system and application patches remediates the vulnerability.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!