|
近日微软所公布的Windows漏洞中,三个为高危漏洞,公告号MS05-050、MS05-051、MS05-052。利用这些漏洞,远程攻击者可以在目标系统上运行代码甚至获取系统权限。受影响的有Windows2K、WindowsXP、WindowsServer2003的各个版本。
即将出现的基于这些漏洞的病毒可能会造成不亚于Zotob、冲击波、震荡波的危害,危害程度及损失大小将取决于Windows用户是否及时安装相关补丁。
为了应对可能出现的大规模蠕虫病毒爆发,请Windows用户及时安装相关补丁(最好进行Windows Update)。
一些修改了Windows默认安装目录的用户在安装安全补丁KB902400后,可能会出现WIndows防火墙无法启动、运行在IIS上的ASP页面会返回ERROR信息、甚至合法用户无法登陆(还需要进一步验证)等问题。 最新的解决方案如下 1. In the %windir%/registration folder, make sure that the Everyone group has READ permissions. 2. In the %windir%/registration folder, make sure that the SYSTEM account has FULL CONTROL permissions. 3. In the %windir%/registration folder, make sure that the Administrators group has FULL CONTROL permissions. 4. In the advanced security properties of the .clb files in the %windir%/registration folder, make sure that the Inherit from parent the permission entries that apply to child objects. Include these with entries explicitly defined here option is selected. 5. Make sure that the Everyone group has one of the following permissions:? Traverse permissions (“List Folder Contents”) on all parent Directories, including %systemdrive%, %windir%, and %windir%\registration ? The Bypass Traverse Checking permission
附:3个高危警告的XP版补丁下载
http://down1.tech.sina.com.cn/download/downContent/2005-10-12/15507.shtml
http://down1.tech.sina.com.cn/download/downContent/2005-10-12/15511.shtml
http://down1.tech.sina.com.cn/download/downContent/2005-10-12/15505.shtml
其他版本Windows用户也可到
http://down1.tech.sina.com.cn/cgi-bin/download/down_list.cgi?class_name=微软下载专区 下载相应补丁
|