Advertisement
Promo

Security threats Toolkit

No fix for 'critical' hole in Windows 98, ME

Joris Evers CNET News

Published: 12 Jun 2006 12:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft will not fix a serious flaw in Windows 98 and Windows Millennium Edition because a patch could break other applications.

The security bug relates to Windows Explorer and could let an intruder commandeer a vulnerable PC, Microsoft warned in April. The software maker has made fixes available for Windows Server 2003, Windows XP and Windows 2000, but it has found that eliminating the vulnerability in Windows 98 and ME is "not feasible", it said.

"To do so would require re-engineering a significant amount of a critical core component of the operating system," Microsoft said in a Thursday update to its MS06-015 security bulletin. "After such a re-engineering effort, there would be no assurance that applications designed to run on these platforms would continue to operate."

Instead, Microsoft recommends that people who still use the older operating systems protect their PCs by using a network firewall that filters traffic on TCP Port 139. "Such a firewall will block attacks attempting to exploit this vulnerability from outside of the firewall," it said.

The software maker even had trouble with its fix for Windows XP. It had to revise the update and release it a second time because the patch caused problems for people who used Hewlett-Packard Share-to-Web software or older Nvidia graphics drivers.

Microsoft is phasing out support for the older operating systems. Windows 98 was released in June 1998, Second Edition followed a year later, and Millennium Edition came out in 2000. Microsoft has been providing fixes for only "critical" flaws the past couple of years and is ending support altogether next month, after its planned 11 July patch release. Windows XP with Service Pack 1 reaches its end of support on 10 October, 2006.

Not providing fixes leaves users vulnerable, but software can't be supported forever, said Michael Sutton, a director at security intelligence company iDefense, a part of VeriSign. "At some point, any vendor has to make a business decision to cease product support, and these products are now 7 to 8 years old," he said.

The older Windows versions have never been secure, said Russ Cooper, a senior scientist at Cybertrust, a security vendor in Herndon, Virginia. "The lack of a 'critical' patch does not weaken these OSes. Instead, it should merely put an end to their perception that they were secure before this fault came to light," he said.

And as far as blocking traffic on port 139 goes, it is a network port that has been abused in the past for attacks, said Don Leatham, director of solutions and strategy at PatchLink. "Most organisations will already have port 139 blocked," he said. "Although it is good that Microsoft is reiterating this, I don't see it being a huge impact."

The best way to secure PCs that run older versions of Windows is upgrading the operating system, Microsoft suggested.

"With the upcoming end (of) support for these products, we strongly recommend that those of you who are still running these older versions of Windows upgrade to a newer, more secure version, such as Windows XP SP2, as soon as possible," Christopher Budd, a staffer in Microsoft's' security response centre, wrote on the team's blog.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
75 out of 151 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters