Microsoft reports access bug

Security personnel from Microsoft Corp. are investigating a newly reported zero-day bug vulnerability in Microsoft operating systems and server systems. The bug, disclosed yesterday by Bill Sisk, security response communications manager for Microsoft, allows escalation of privilege to occur for authenticated users under specific conditions.



Users on a given system can elevate their access privileges to LocalSystem in Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008, according to Sisk. It could cause havoc by giving an authenticated user inappropriate write, delete and change privileges.



The fix for this potential problem is still in the works.



"Microsoft has issued Security Advisory (951306) to provide guidance to affected customers to help them protect themselves. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process," Sisk wrote.



The advisory is specifically addressed to IT pros overseeing an environment where several logged-in users provide their own code. Typically, programmers or administrators would have such rights. Specific cases include users working with Microsoft's Internet Information Services, which supports Web-based operational services, and SQL Server.



To address the issue, IT shops should keep at least a cursory, if not detailed, log of daily access to critical systems and applications. A segregation of duties program may be helpful too. Under such a regimen, programmers aren't deploying applications in a live production environment, and neither are the testers of those applications.



In the security advisory, Microsoft contends that companies providing space on their servers for use by off-site clients, or hosting providers, "may be at increased risk from this elevation of privilege vulnerability."



This article was originally publinsed April 18 at RedmondMag.com, an affilate Web site of GCN.com. RedmondMag.com and GCN.com are 1105 Media Inc. properties.

Featured

  • business meeting (Monkey Business Images/Shutterstock.com)

    Civic tech volunteers help states with legacy systems

    As COVID-19 exposed vulnerabilities in state and local government IT systems, the newly formed U.S. Digital Response stepped in to help. Its successes offer insight into existing barriers and the future of the civic tech movement.

  • data analytics (Shutterstock.com)

    More visible data helps drive DOD decision-making

    CDOs in the Defense Department are opening up their data to take advantage of artificial intelligence and machine learning tools that help surface insights and improve decision-making.

Stay Connected