Microsoft Windows Name Service (WINS) Said To Be Vulnerable - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Software // Enterprise Applications

Microsoft Windows Name Service (WINS) Said To Be Vulnerable

Microsoft is recommending that network administrators remove WINS if it's not needed.

Microsoft says it's looking into reports of a security screw-up in Windows Internet Name Service (WINS), a component of its most popular server software, including Windows NT 4 Server, Windows 2000 Server, and Windows Server 2003.

In a posting to its online support center, Microsoft said: "this security issue could make it possible for an attacker to take control of a WINS server remotely." As of Nov. 26, however, Microsoft said it didn't know of any actual exploit of the possible vulnerability.

Microsoft recommended that network administrators remove WINS if it's not needed, and/or block TCP and UDP ports 42 at the firewall.

WINS is often used by enterprises for name registration and name resolution functions, so it may be impossible to disable without impacting the network. Blocking TCP/UDP ports 42, however, will guard the systems behind the firewall from possible attack.

Danish security firm Secunia tagged the vulnerability as "moderately critical," while the SANS Institute's Internet Storm Center said in an advisory that until Microsoft releases a patch, its best advice was to follow Microsoft's and block unneeded ports, such as port 42.

"So far, we doubt this will be a huge thing," said the Center, "but we might be wrong."

The Storm Center also blasted the researcher, Nicolas Waisman, who reported the vulnerability, claiming that his disclosure prior to a patch being available was "irresponsible."

More information on steps to take to protect WINS-running servers can be found on the Microsoft Web site.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
Commentary
Enterprise Guide to Edge Computing
Cathleen Gagne, Managing Editor, InformationWeek,  10/15/2019
News
Rethinking IT: Tech Investments that Drive Business Growth
Jessica Davis, Senior Editor, Enterprise Apps,  10/3/2019
Slideshows
IT Careers: 12 Job Skills in Demand for 2020
Cynthia Harvey, Freelance Journalist, InformationWeek,  10/1/2019
White Papers
Register for InformationWeek Newsletters
Video
Current Issue
Getting Started With Emerging Technologies
Looking to help your enterprise IT team ease the stress of putting new/emerging technologies such as AI, machine learning and IoT to work for their organizations? There are a few ways to get off on the right foot. In this report we share some expert advice on how to approach some of these seemingly daunting tech challenges.
Slideshows
Flash Poll