LLSSRV Clarifications [Immunity]

Dave Aitel <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.announce
Message-ID <[email protected]>
Immunity is happy to announce the release from VSC of a new paper to our 
public website regarding the technical details of the llssrv 
vulnerability Microsoft released on February 8th, 2005. Along with this 
paper, we've released a reliable, language-independant exploit to the 
CANVAS distribution.

As stated in MS05-010, LLSSRV is not remotely exploitable on Windows 
2000 Server SP3 and 4 without authentication. However, it is remotely 
exploitable in Windows 2000 Advanced Server SP 3 and 4 without 
authentication. This information, missing from MS05-010, is a perfect 
example as to why fully independant third party security information and 
exploit code provide a key link in an organization's ability to 
understand and evaluate the risk posted by vulnerabilities.

Further details, vulnerability release scheduling, and other information 
are available here:
http://www.immunitysec.com/resources-advisories.shtml

Thanks,
Dave Aitel
Immunity, Inc.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.