ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft patches 'important' XP, Windows Server 2003 flaw

Ina Fried CNET News.com

Published: 12 May 2004 08:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft detailed on Tuesday a new vulnerability in Windows XP and Windows Server 2003 that could enable an attacker to remotely execute malicious code.

The software maker described the problem as "important," its second-highest rating for such problems. Antivirus software maker Symantec, meanwhile, characterised the vulnerability as "high risk", citing the impact that there could be if the vulnerability was successfully exploited.

The flaw exists in the way Windows' Help and Support Centre validates information that is sent to it. The software maker released a patch for the vulnerability and urged customers to "install the update at the earliest opportunity." The patch is posted to the company's security Web site, as is a bulletin outlining the flaw.

The bulletin was released as part of Microsoft's regularly scheduled monthly security update, according to Stephen Toulouse, a security programme manager in the Microsoft Security Response Centre. As for the rating level, Toulouse said Microsoft typically only deems vulnerabilities "critical" -- the highest level -- if they can be exploited without the user taking any action.

The announcement of the flaw comes as Microsoft works to battle the outbreak of the Sasser worm and its variants. The software giant has been touting the arrest of a German teenager believed responsible for Sasser and other recent infections.

However, unlike Sasser, the latest vulnerability cannot be exploited simply through an email worm. According to Symantec and Microsoft, there are a number of steps the user would need to take in order for their system to be compromised. Most likely, an attacker would have to host a Web site with a page designed to exploit the vulnerability and convince a user with an unpatched system to visit the site and perform several actions.

Microsoft warned of the vulnerability that led to Sasser in a bulletin last month.

The patch released on Tuesday by Microsoft to fix the new flaw also makes two other changes designed to make Windows more secure. First, Microsoft removed a feature in Windows XP that gave users the option to upgrade a DVD decoder, in a move designed to prevent malicious exploitation of the feature.

Second, Microsoft eliminated a feature in the Help and Support Centre that sometimes prompts people to send out information on their system's hardware after they run the "Found new hardware" wizard. Now, instead of being prompted to send their hardware information, users will now get an error message at the end of installing new hardware.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
64 out of 103 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

SQL and Windows Server Contract Role- Wiltshire

You should have the experience with SQL Server 2005, Windows Server 2003, Exchange, Active Directory, VMWare, Symantec, Backup Exec, Windows XP and ...

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Working closely with customers to understand their technical requirements and installing and configuring the solutions to meet these. Technical ...

Project Manager (Online, End-To-End Web-Site builds )

Project Manager to work for a global Media & Publishing organisation. Our client has offices world-wide and have over 300 publications and related ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment