Microsoft Releases Two New Security Warnings

Microsoft has released two new security warnings, one regarding Microsoft Windows Media Services and one regarding Microsoft Systems Management Server (SMS). The vulnerability in Windows Media Services could allow denial of service attacks against a streaming media server, and the vulnerability in SMS could allow a user to gain elevated privileges on the local machine.

With Windows Media Services, the handshake sequence between a Windows Media server and a Windows Media Player is asynchronous, because certain resource requests are dependent on the successful completion of previous ones. If the client-side handshake packets are sent in a particular, misordered sequence, with certain timing constraints, the server will attempt to use a resource before it has been initialized and will fail catastrophically, causing the Windows Media Unicast Service to crash. The Windows Media Unicast Service can be put back into normal operating condition by restarting the service, but any sessions that were in effect at the time of the crash would need to be restarted.

Microsoft Windows Media Services 4.0 and 4.1 are affected. The patch for Windows NT Server 4.0 is available at and the patch for Windows 2000 Server is available at

With SMS, if the SMS 2.0 Remote Control feature has been installed and enabled on a machine, the folder in which the remote agent resides has its permissions set to Everyone Full Control by default. If a malicious user replaced the client code with code of his choosing, it would run automatically in a system context the next time he rebooted the machine and logged on. The vulnerability exists only if the Remote Control feature has been enabled. No other SMS features are affected by it.

Microsoft Systems Management Server 2.0 is affected by this vulnerability. The patch for X86 machines is available at and the patch for Alpha machines is available at - Isaac Slepner

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.


  • Skype Room Systems Rebranded as 'Microsoft Teams Rooms'

    Microsoft on Wednesday announced the rebranding of its Skype Room Systems product line of partner-built videoconferencing and meeting room devices, which are now called "Microsoft Teams Rooms."

  • Intel's 'Cascade Lake' Datacenter Chips Tackle AI Inference

    Amid all the flash of this month's Consumer Electronics Show (CES), there was an unlikely datacenter announcement: Intel is now shipping its new Xeon Scalable CPU.

  • Azure DevOps Server 2019 Now at Release Candidate 2

    Microsoft released Azure DevOps Server 2019 Release Candidate 2 (RC2), according to a Tuesday announcement.

  • Cloud IT Infrastructure Spending Starting To Take the Lead

    IDC this month published findings on revenues from cloud IT infrastructure spending in the third quarter of 2018, based on server, storage and Ethernet switch sales.

comments powered by Disqus
Most   Popular

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.