This patch eliminates several security vulnerabilities that could allow a range of effects, from denial of service attacks to, in some cases, privilege elevation. Several vulnerabilities have been identified in the Windows NT 4.0 and Windows 2000 implementations of LPC and LPC ports:
- The Invalid LPC Request vulnerability, which affects only Windows NT 4.0. By levying an invalid LPC request, it would be possible to make the affected system fail.
- The LPC Memory Exhaustion vulnerability, which affects both Windows NT 4.0 and Windows 2000. By levying spurious LPC requests, it could be possible to increase the number of queued LPC messages to the point where kernel memory was depleted.
- The Predictable LPC Message Identifier vulnerability, which affects both Windows NT 4.0 and Windows 2000. Any process that knows the identifier of an LPC message can access it; however, the identifiers can be predicted. In the simplest case, a malicious user could access other process LPC ports and feed them random data as a denial of service attack. In the worst case, it could be possible, under certain conditions, to send bogus requests to a privileged process in order to gain additional local privileges.
- A new variant of the previously-reported Spoofed LPC Port Request vulnerability. This vulnerability affects Windows NT 4.0 and Windows 2000, and could, under a very restricted set of conditions, allow a malicious user to create a process that would run under the security context of an already-running process, potentially including System processes.
Visit the LPC Vulnerability FAQ for more information.
People who downloaded this software also downloaded...
SpyWall Anti-Spyware 1.4.3.1
Remove spyware and keep them out with a browser sandbox.
Cute Password Manager 2008.1.3.8
Log into Web sites and fill forms with just a few mouse clicks.
SolidShare 2.6.11
Connect anyone on your network to the Internet with one ISP account and one modem.
Watch N Catch 1.0
Protect your assets with an IP-based video surveillance system.
EasyCryptor 1
Encrypt and decrypt any files and send results to your e-mail address.
Child Computer Lock 1.6
Protect your privacy by locking your computer.
Digital Vault 2.1.5.1
Encrypt, hide, and protect your personal data.
Portable Vault 2.0.0.7
Protect sensitive information on your portable USB Drive.
ItsCryptic 1
Protect files confidential to you or your business by encrypting them.
n-Pass2Go 2.7.0.465
Store and manage your passwords and encrypted data on any removable device.






