ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft upgrades flaw to 'critical'

Published: 13 Dec 2002 08:39 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

For the second time in a week, Microsoft acknowledged that its initial estimation of a software flaw underrated the true threat posed by the vulnerability.

The Redmond, Washington giant said on Thursday it plans to change the severity of a vulnerability in software common to Internet Explorer and other Windows applications from "important" to "critical". The move was prompted by an in-depth analysis written by the security researchers who found the flaw.

"We believe that there is enough of a suggestion in this data to take action to protect customers," said Steve Lipner, director of Microsoft's security response center. "We are going to change the bulletin."

The advisory originally said the vulnerability could be used only to make Internet Explorer fail. However, after two weeks of research, security firm eEye Digital Security warned PC users that the flaw, which occurs in the handling of the open-source image format PNG (portable network graphics), could enable malicious programs to run on the victim's system.

"It was very misleading to call it a (moderate) risk," said Marc Maiffret, chief hacking officer for eEye. "It is an exploitable vulnerability that can attack computers just by (the user) looking at an image."

This is the second time in a week that Microsoft has had to upgrade the severity of a vulnerability.

In early December, Microsoft upgraded to "critical" another "moderate" flaw after the company acknowledged that it has missed important details about how the vulnerability could be exploited to attack a system. Microsoft added the "important" classification in November as the second-most severe rating for flaws.

Microsoft's Lipner said that the company is looking into how to avoid such mistakes in the future.

"Building these exploits is more art than science," he said. "We are reviewing what we do to reproduce and evaluate these things."

On Wednesday, Microsoft warned of eight flaws in its version of the Java virtual machine, the worst of which "could enable an attacker's Java applet to gain control over another user's system", according to the alert. The malicious program could let an attacker add, delete or change data on the victim's computer as well as run programs.

In the end, eEye's Maiffret chalked up the incident to mischance.

"Mistakes happen," he said. "We just hope that other companies take the extra step to get the right information out."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
52 out of 93 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Business Analyst ( OO , Java ) - London

Primary Responsibilities - Work with Financial Engineers and Developers to conduct sophisticated validation of existing and new models; develop test ...

Applications Coordinator

Coordinator will include: * Leading the Application Services Team in the delivery of professional, timely, effective and high-quality applications ...

Websphere MQ WBIMB Developer Required- Java ESQL

Eclipse, ClearQuest, MQ Explorer, JExplorer, LINUX, Solaris and ZOS. Websphere MQ WBIMB (Message Broker) V5 or V6 Developer with Java development ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains