ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise applications Toolkit

Windows ME flaw exposed

Jim Hu CNET News.com

Published: 27 Feb 2003 16:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has issued a software patch for what it calls a critical security flaw in its Windows Millennium Edition operating system, according to the company's Web site.

The security flaw is a "buffer run" vulnerability, which, if exploited, lets an attacker execute software programs on a victim's computer. The flaw could allow attackers to delete files, run software code and modify programs that appear to have originated locally on the victim's PC, according to the warning on Microsoft's Web site.

Microsoft has issued a patch for the flaw that can be downloaded by Windows ME users.

The software titan is one year into a major push to make its applications more secure, but has acknowledged that much work remains to be done.

The buffer vulnerability was discovered in the Windows ME Help and Support Centre, which allows people to execute links using the "hcp://" prefix in a Web link instead of "http://." Phoney links using the "hcp://" prefix, which contains the flawed buffer, would then allow an attacker to run software on the victim's computer, the notice said.

Microsoft added that the phoney links could be sent to unsuspecting victims via email or could be hosted on a Web site.

An attacker could, in some circumstances, trigger a software program to execute automatically by sending it via email. However, people using Outlook Express 6.0 or Outlook 2002 as their default email systems, or Outlook 98 and 2000 with a security update, would have to click on an emailed link to run the attacker's software.

The patch was originally posted on Microsoft's Web site on Wednesday.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
37 out of 78 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Head of Programs BRISTOL

My FTSE listed client requires for a Programme Manager to lead and Managing a team of Project Managers in both Bristol and Berlin. Your ...

Project Manager (Online, End-To-End Web-Site builds )

Project Manager to work for a global Media & Publishing organisation. Our client has offices world-wide and have over 300 publications and related ...

SAP Project/Programme Manager required - 75k +

The company are easily accessible and based in an idyllic area of countryside with fantastic rail and road links to major towns and cities. A Giant ...

Featured Talkback

The internet is going to have do a lot of maturing before it is ready for this kind of traffic. Security is always going to be a problem, connectivity is poor, and most business's are unwilling for their employees to have open access.

By: ator1940

Read full story:
Microsoft prepares to take Office online