ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Windows XP, Office and SQL Server open to new attacks

Matthew Broersma ZDNet.co.uk

Published: 17 Oct 2002 13:47 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft late on Wednesday warned of three new bugs in its software, including a flaw in SQL Server 7.0 and 2000 that could allow an unauthorised user to execute particular administrative functions called Web tasks. The company also disclosed a flaw in Windows XP that could allow an attacker to delete files, and one in Office that could lead to information disclosure.

The SQL Server bug received Microsoft's highest rating of "critical" because it could allow a low-privileged user to execute high-privilege functions. A flaw in the way the server handles permissions could allow any user who authenticates to a server to run, delete, insert or update Web tasks created by other users. Web tasks create a task that executes database queries and uses the results to produce a Web page.

Any Web task executed could be run in the context of the user who created the Web task, Microsoft said. This would typically be the SQL Server Agent service account. However, by default this account runs with the privileges of a domain user rather than with higher-level system privileges, Microsoft said.

The company added that attackers could only exploit the bug if they were already authenticated to the server, barring most of the general public. The attacker would also be unable to create new Web tasks. More information and a patch are available on Microsoft's Web site.

David Litchfield was credited with originally reporting the bug to Microsoft, and Martin Rakhmanoff also contributed to the investigation, Microsoft said.

A second flaw affects the Windows XP version of Help and Support Center, which contains help files and access to Windows Update, among other features. A mistake in permissions could allow a malicious Web page or HTML email to call on a file within Help and Support Center, causing it to erase any file on the user's PC.

However, the attacker would have to know the exact location of the file he or she wished to delete, and would have to entice the victim to view a specially-formed Web page or HTML email. Windows XP Service Pack 1 eliminates the bug, and Internet Explorer 6.0 Service Pack 1 would prevent Help and Support Center from being launched from Outlook or Outlook Express, Microsoft said.

A patch for this flaw was posted on Microsoft's site.

The third flaw could allow a specially modified Word or Excel document to gather information from a PC that could later be retrieved from the document by an attacker. The attack uses features in Word and Excel designed to update documents from an outside source.

A flaw would allow the Word or Excel document to update itself with the contents of a file from the user's computer, without giving any indication that this had happened. But to succeed the victim would have to be convinced to receive a document, modify it and then return it to the attacker, Microsoft said. A patch was made available here.

Microsoft has been on a drive to give all its products watertight security since earlier this year. However, it continues to regularly issue new warnings, the three latest bugs bringing to 61 the total number of notifications this year.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
63 out of 98 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Calypso App Support Analyst - Banking - London - 400-50/day *URGENT*

Strong experience supporting the Calypso application essential, and the ability to execute day-to-day support tasks, production support, capacity ...

Requirements Analyst- West London- 35-45,000

To design and execute the test scenarios and test scripts. The main purpose of the role will be to analyse, document, and propose solutions for large ...

SAP Database Administrator Farnborough

Key Tasks & Responsibilities: - To administer the customer, vendor and material databases maintained for all Getronics subsidiaries - Maintain ...

Discussions

0xyGen 0xyGen

Please help me in choosing web hosting

Sunday 20 July 2008, 10:32 AM

1 post
1000030281 1000030281

Facebook Bans Firefox 3

Sunday 20 July 2008, 2:33 AM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal