Title: Microsoft Hotfix Conflict Vulnerability
Severity: MODERATE
Description:
System catalogs within Windows 2000 contains cryptographic hashes of system files protected by Windows File Protection, the catalog is electronically protected with a key prior to release. These system files are protected to ensure that they are not replaced or modified in any way.
Microsoft releases hotfixes which patch different security issues for various MS environments, the catalog included in hotfixes contain all fixes issued to date. Windows File Protection uses the electronically signed catalog to determine what hotfix is valid.
Previously implemented hotfixes can be uninstalled from a Windows 2000 machine, leaving the machine vulnerable to current security issues. The catalog file (Sp2.cat) within Windows 2000 Post-Service Pack 1 (English Version) Hotfixes, has been improperly versioned. Windows File Protection could detect previously installed hotfixes as invalid, thus removing the hotfix and potentially leaving the system susceptible to vulnerabilities. Previous hashes of the system catalog that do not correspond to the system files protected by Windows File Protection, would be replaced.
It should be noted that the hotfix subject to this issue (Windows 2000 Post-Service Pack 1 (English Version)) was made available through December 18, 2000
Successful exploitation of this vulnerability could assist in further attacks against the victim.
Affected Products:
- Avaya DefinityOne Media Servers
- Avaya IP600 Media Servers
- Avaya S3400 Message Application Server
- Avaya S8100 Media Servers
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Server SP1
References:
- Microsoft: Microsoft Security Bulletin (MS01-005)
- Microsoft: Microsoft Security Bulletin (MS01-005): Frequently Asked Questions
- Microsoft: Qfecheck.exe Verifies the Installation of Windows 2000 Hotfixes
- Microsoft: Updated Sp2.cat Available to Resolve Versioning Issues with Post Service Pack 1
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.