Security Advisory |
|||||||||
Microsoft has released a security bulletin (MS04-007) describing a vulnerability in the parsing of ASN.1 data that could result in remote code execution. This is not a vulnerability in VanDyke applications and there is no need to update VanDyke applications to address this issue. It is, however, a critical vulnerability in affected versions of Windows for which Microsoft updates should be applied immediately. |
|||||||||
Posted: February 13, 2004 Description Microsoft has released a security bulletin (MS04-007) describing a vulnerability in the parsing of ASN.1 data that could result in remote code execution. This vulnerability is present in many versions of Windows (including Windows NT/2000/XP/2003). To exploit this vulnerability, an attacker must force a computer to decode malformed ASN.1 data. VanDyke applications that run on Windows can be configured in such a way (such as using Kerberos or X.509 authentication methods) that they could parse ASN.1 data using the system libraries that contain this vulnerability. Therefore, the use of VanDyke applications on unpatched systems could be one way to exploit this vulnerability. Note, this is not a vulnerability in VanDyke applications and there is no need to update VanDyke applications to address this issue. It is, however, a critical vulnerability in affected versions of Windows for which Microsoft updates should be applied immediately. Please refer to the following Microsoft Security Bulletin for more information on the vulnerability, affected versions of Windows, and update procedures: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-007
|
VanDyke Software uses cookies to give you the best online experience. Before continuing to use this site, please confirm that you agree to our use of cookies. Please see our Cookie Usage for details.
Here you can control cookies using the checkboxes below. Some cookies are essential for the use of our website and cannot be disabled. Others provide a convenience to the user and, if disabled, may reduce the ease of use of our site. Finally, some cookies provide anonymous analytic tracking data that help us provide the user with a richer browsing experience. You can elect to disable these cookies as well.