ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise applications Toolkit

More flaws threaten Windows

Published: 13 Jun 2002 14:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft posted three advisories on its Web site on Wednesday detailing several recently discovered flaws, one of which was deemed critical for Windows NT and 2000 servers.

The software giant dubbed "critical" a buffer overflow in its remote access service (RAS) software, which is a native element in the Windows NT 4.0, Windows 2000 and Windows XP ooperating systems. The security hole could allow an intruder to run any code, the advisory stated.

"An attacker who successfully exploited this vulnerability could gain complete control over the machine, thereby gaining the ability to take any desired action," said the advisory.

Another release detailed two flaws in the way Microsoft SQL Server handles the XML data exchange format, and a third release warned that Web servers with HTR scripting turned on are also in danger. HTR is an older, obsolete type of scripting now replaced by active server pages.

The new advisories point to the latest of a number of flaws Microsoft has identified in recent months, at the same time that it's been running a high-profile campaign to stamp out such problems.

In January, chairman Bill Gates signaled a new direction for the company in an e-mail to all his employees, asking them to help make Microsoft's software "trustworthy." The company has been toiling to button up its products and exterminate critical bugs, but seems to still have its work cut out for it.

The three advisories bring Microsoft's total for the year to 30, detailing nearly 40 flaws.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
38 out of 95 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Script Developer. London. 35,000 - 45,000. Java / C Programming

You will have extensive knowledge of programming in Java and / or C- Based Visual Scripting Language. Knowledge of Crystal Reports is useful as is NT ...

SQL Report Analyst / Developer (Microsoft SQL Server 2005, T-SQL) Bedfordshire, South East

Applicants will also require experience in T-SQL scripting. Job Title: SQL Report Analyst / Developer (Microsoft SQL Server 2005, T-SQL) ...

IT Support Engineer (Terminal Services 2003,Wins Server,AD,VMWare)

Successful candidates will be working in a Windows Server team, administering, installing and troubleshooting for Windows NT, 2000/2003 server ...

Featured Talkback

The internet is going to have do a lot of maturing before it is ready for this kind of traffic. Security is always going to be a problem, connectivity is poor, and most business's are unwilling for their employees to have open access.

By: ator1940

Read full story:
Microsoft prepares to take Office online