cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
246
Views
4
Helpful
1
Replies

MS Security Bulletin MS03-010

technology
Level 1
Level 1

Just received notice of this vulnerability. Does Cisco have a response to this? Should we be concerned with our CM and Unity servers?

-----

Flaw in RPC Endpoint Mapper Could Allow Denial of Service Attacks (331953)

Originally posted: March 26, 2003

Summary

Who should read this bulletin: Customers using Microsoft® Windows® NT 4.0, Windows 2000, or Windows XP

Impact of vulnerability: Denial of Service

Maximum Severity Rating: Important

Recommendation: Customers should install the patch at the earliest opportunity

-----

Thanks!

1 Reply 1

dgoodwin
Cisco Employee
Cisco Employee

Hi,

In response to CallManager specifically:

Since Microsoft has rated the severity of this flaw as "Important" this hotfix will not be rolled out to CCO in a separate hotfix package. Instead, it will be rolled into the next WinOSUpgrade package, which will be 2000.2.3 support patch J. It should be posted on or around April 1.

In regards to Unity, please read this URL:

http://www.cisco.com/univercd/cc/td/doc/product/voice/c_unity/sysreq/31_sysrq.htm#1356878

The quick answer is that Win2k Service Packs take up to 60 days for us to certify as acceptable on a Cisco Unity server. As long as you are running a supported Windows Service Pack level, the individual hotfixes are supported.