- Quick specs
- Price: Update
- Operating system: Windows 2000/XP
- Date added: October 30, 2002
- Total Downloads: 15
- Downloads last week: 1
- See full specifications
- Average user rating: Be the first to rate this product!
Publisher's description
From Microsoft :Windows 2000 and Windows XP natively support Point-to-Point Tunneling Protocol (PPTP), a Virtual Private Networking technology that is implemented as part of Remote Access Services (RAS). PPTP support is an optional component in Windows NT 4.0, Windows 98, Windows 98SE, and Windows ME.
A security vulnerability results in the Windows 2000 and Windows XP implementations because of an unchecked buffer in a section of code that processes the control data used to establish, maintain and tear down PPTP connections. By delivering specially malformed PPTP control data to an affected server, an attacker could corrupt kernel memory and cause the system to fail, disrupting any work in progress on the system.
The vulnerability could be exploited against any server that offers PPTP. If a workstation had been configured to operate as a RAS server offering PPTP services, it could likewise be attacked. Workstations acting as PPTP clients could only be attacked during active PPTP sessions. Normal operation on any attacked system could be restored by restarting the system.
More popular Operating Systems & Updates downloads
- 20,499 downloads 1. DriverMax
- 16,510 downloads 2. CNET TechTracker app
- 7,328 downloads 3. Windows 7 USB/DVD Download Tool
- 6,706 downloads 4. Microsoft Windows XP Home Edition
- 5,747 downloads 5. Windows XP Media Center Edition
- See all Operating Systems & Updates downloads
User reviews
Write your own review Be the first one to review Microsoft Security Bulletin MS02-063 Q329834 and share your experience with the CNET community!
Submit your review
- See more CNET content tagged:
- Microsoft Windows,
- Microsoft Windows 2000,
- PPTP,
- server,
- workstation


