ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

EEye: More Microsoft bugs on the way

Munir Kotadia ZDNet.co.uk

Published: 11 Feb 2004 13:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

EEye, the company that originally discovered a critical Windows bug patched by Microsoft on Tuesday, says it is waiting on fixes for seven more Microsoft bugs -- three of them meriting a "high" severity rating.

Microsoft released a patch for Windows on Tuesday that fixed one of the most severe security holes ever found in the operating system. Microsoft said it took more than six months to fix the problem and to make sure the patch was thoroughly tested. During this time, the vulnerabilities could have been exploited by another MSBlast-type attack, allowing a virus to rapidly infect a large number of Internet-connected computers, according to security experts.

EEye now says it has reported another seven as-yet-unpatched bugs to Microsoft, some as long as five months ago. The company is listing the report dates and seriousness of the bugs on its Web site, but will reveal no further information until Microsoft has released fixes.

Two of eEye's most dangerous flaws were reported to Microsoft on 10 September, 2003, while the third was brought to the company's attention a month later. According to eEye's Web site, the fixes are overdue by 94 and 66 days respectively.

EEye is one of many security research organisations reporting vulnerabilities to Microsoft, but is one of the few which allows the public to monitor the progress of its bug reports. Some researchers have been known to release public warnings about specific flaws if they judge a software vendor is taking too long to patch, a practice which vendors have heavily criticised.

According to eEye's Web site, full details of each vulnerability "will be disclosed to the public at the time a patch is released from the vendor".

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
69 out of 127 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Market Data BA (Vendor, Neogotiations, Costs) BANKING FX/EQUITES

This is to join a global team of 13 Market Data Business Analysts who are responsible for management of Vendor Prestigious 1st Tier Investment Bank ...

Market Data Analyst (MDS,Vendor,Costs,Reuters) HEDGE FUND

The role of the Market Data Analyst will be to identify the best product for end users needs, manage the relationships with business units at all ...

Business Analyst, Gas and Power, Vendor, London

This vendor has a solid client base both in the US and throughout Europe. This vendor prides itself on being cutting edge and is continuously ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.