Revised February 24, 2004
February 16, 2004
Products Affected
|
Product |
Comments |
|---|---|
|
ICM Enterprise |
4.6.2 and 5.0, all service releases |
|
IPCC Enterprise |
4.6.2 and 5.0, all service releases |
|
ICM Hosted |
4.6.2 and 5.0, all service releases |
|
IPCC Hosted |
4.6.2 and 5.0, all service releases |
|
Cisco Internet Service Node |
Versions 1.0, 2.0 and 2.1 |
Problem Description
As of February 10, 2004 Microsoft has released the following security updates:
MS04-007 Critical
ASN.1 Vulnerability Could Allow Code Execution (828028)
Affected Software:
-
Microsoft Windows NT Server 4.0 Service Pack 6a
-
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
-
Microsoft Windows 2000 Service Pack 2, Service Pack 3, and/or Service Pack 4
MS04-006 Important
Vulnerability in the Windows Internet Naming Service (WINS) Could Allow Code Execution (830352)
Affected Software:
-
Microsoft Windows NT® Server 4.0 Service Pack 6a
-
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
-
Microsoft Windows 2000 Server Service Pack 2, Service Pack 3, and/or Service Pack 4
Non Affected Software:
-
Microsoft Windows NT® Workstation 4.0 Service Pack 6a
-
Microsoft Windows 2000 Professional Service Pack 2, Service Pack 3, and/or Service Pack 4
MS04-005 Important
Vulnerability in Virtual PC for Mac could lead to privilege elevation (835150)
Affected Software:
-
Macintosh systems
MS04-004 Critical
Cumulative Security Update for Internet Explorer (832894)
Affected Software:
-
Microsoft Windows NT Server 4.0 Service Pack 6a
-
Microsoft Windows NT Server 4.0 Terminal Server Edition, Service Pack 6
-
Microsoft Windows 2000 Service Pack 2, Service Pack 3, Service Pack 4
MS03-051 Critical
Buffer Overrun in Microsoft FrontPage Server Extensions Could Allow Code Execution (813360)
Affected Software:
-
Microsoft Windows 2000 Service Pack 2, Service Pack 3
Non Affected Software:
-
Microsoft Windows NT Server 4.0, Service Pack 6a
-
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
-
Microsoft Windows 2000 Service Pack 4
For additional information on Microsoft security updates, see the Microsoft Security Updates page.
Background
Cisco evaluates Microsoft security updates for potential impact to Cisco Customer Contact Business Unit (CCBU) products. The qualification process results in one of four categorical ratings being applied to a given update: Impacting, Not Impacting, Deferred, or Not Applicable.
The four ratings are defined as follows:
-
Impacting (CCBU product impact testing is performed within a predefined window of when the security update is released by Microsoft)
-
The update is labeled by the vendor as Critical or Important or is otherwise of special interest to CCBU customers
-
It potentially affects some Contact Center component or functionality (or is basic to the OS and affects all operations for any software)
-
It must apply to the latest CCBU specified Service Pack(s)
-
-
Not Impacting (CCBU products are not impacted by the security update and no further testing is performed)
-
The update is labeled by the vendor as Critical or Important or is otherwise of special interest to CCBU customers
-
It does not affect any CCBU component or functionality or any basic OS functionality
-
It must apply to the latest CCBU Specified Service Pack(s)
-
-
Deferred (Validation is typically deferred to the next Service Release, Maintenance Release, and subsequent Major/Minor Releases)
-
The update is labeled by the vendor as Moderate or Low
-
It affects some CCBU component or functionality (or is basic to the OS and affects all operations for any software)
-
It must apply to the latest CCBU Specified Service Pack(s)
-
-
Not Applicable (The security update does not apply to any current CCBU product. No further qualification is required)
-
The security update does not apply to the latest CCBU Specified Service Pack(s), regardless of CCBU Enterprise product applicability or vendor-rated severity.
-
For the security updates listed in the Product Description section of this bulletin, Cisco has assigned the updates to the following categories:
Impacting
MS04-004. Cumulative Security Update for Internet Explorer (832894)
MS04-007. ASN.1 Vulnerability Could Allow Code Execution (828028)
Deferred
MS04-006. Vulnerability in the Windows Internet Naming Service (WINS) Could Allow Code Execution (830352)
Not Applicable
MS04-005. Vulnerability in Virtual PC for Mac could lead to privilege elevation (835150)
MS03-051. Buffer Overrun in Microsoft FrontPage Server Extensions Could Allow Code Execution (813360)
Customers should follow Microsoft's guidelines regarding when and how they should apply these updates. Refer to the Microsoft website for full details of the potential exposure from the caveats referenced in the Microsoft Security page.
Problem Symptoms
It is important to point out that Cisco Contact Center Support has not had any cases pertaining to this threat recorded from our customer base as of February 19, 2004.
Workaround/Solution
Cisco has assessed, and where deemed appropriate, validated the Microsoft security patches addressed in this bulletin. Cisco recommends that Contact Center customers separately assess all security patches released by Microsoft and install those deemed appropriate for their environments. Cisco will continue to provide a service of separately assessing and where necessary, validating higher severity security patches that are relevant to the Contact Center Enterprise software products.
Visit the Microsoft website to acquire the fixes. Keep in mind that you should download the appropriate fixes based on the version of the Microsoft operating system deployed in your environment and service pack level.
DDTS
There are no Cisco defects logged for issues related to the above patches as of February 19, 2004.
For More Information
If you require further assistance, or if you have any further questions regarding this field notice, please contact the Cisco Systems Technical Assistance Center (TAC) by one of the following methods:
Receive Email Notification For New Field Notices
Product Alert Tool - Set up a profile to receive email updates about reliability, safety, network security, and end-of-sale issues for the Cisco products you specify.