ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft issues alert on three 'critical' flaws

Published: 21 Aug 2003 08:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft alerted PC users to three critical security flaws in Internet Explorer and Windows on Wednesday, as the MSBlast worm and its variants used a previous vulnerability in Windows to spread across the Net for a second week.

The software giant released a cumulative patch for Internet Explorer that fixes several vulnerabilities previously disclosed by the company, and it re-released an advisory for Microsoft's SQL Server software, warning that a flaw in that program actually affects most Windows users. The patch is available from Microsoft's Web site.

Users who don't patch their systems could leave the computers open to attack through a fake Web page or an HTML email that contains the specific exploit code, said Stephen Toulouse, security program manager for Microsoft's security response centre.

"The Internet Explorer bulletin is rated as 'critical' across all platforms except Windows 2003," Toulouse said. A critical rating is the highest grade that Microsoft assigns to its alerts. The flaws were rated "moderate" -- the second-lowest grade -- for Windows 2003, the latest version of the operating system.

On Wednesday, security-software maker Symantec said that MSBlast, a worm that takes advantage of a month-old vulnerability in Microsoft's OS, had infected almost 700,000 computers. A variant of the worm, MSBlast.D or Nachi, had infected more than 525,000 computers since it began to spread on Monday.

Although critical, the latest vulnerabilities are far less likely to become fodder for a worm writer because a victim would have to go to an attacker-owned Web page to be attacked.

The Internet Explorer vulnerabilities involve the fact that the software doesn't check the type of an object returned from a Web server, and because a flaw exists in the browser's cross-domain security model, Microsoft stated in its advisory.

The other critical vulnerability affects all supported versions of Windows and was originally thought to be a vulnerability in Microsoft's SQL Server but is, in fact, a flaw in the omnipresent Microsoft data access component (MDAC). Windows 2003 doesn't have the vulnerable software installed by default, but a user could have downloaded the programs and so could be vulnerable.

Microsoft's Toulouse pointed out the silver lining in the latest vulnerabilities: the flaws affected Windows 2003 to a lesser degree.

"I think it is an observable bit of progress for Trustworthy Computing," Toulouse said. "The default settings of the operating system are more secure."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
96 out of 193 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

VB Developer - VB6, SQL Server - Nottingham/Derby

VB Developer - VB6, SQL Server - Nottingham/Derby A leading retailer based in Nottingham has an URGENT requirement for a VB Developer to join its ...

Junior SQL Server / .Net Developer - Upto 35,000 - SW London

Junior SQL Server /.Net Developer required to work for retail software services company based in Richmond. They are a very well renowned company with ...

SQL Report Analyst / Developer (Microsoft SQL Server 2005, T-SQL) Bedfordshire, South East

Job Title: SQL Report Analyst / Developer (Microsoft SQL Server 2005, T-SQL) Bedfordshire, South East Salary: Starting Salary circa 35,000 - 40,000 ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment