Advertisement
Promo

Desktop platforms Toolkit

Why did Microsoft take so long?

Published: 13 Feb 2004 15:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Whatever time frame it takes to fix something, you could always argue that it could have been made somewhat shorter," said Chris Wysopal, vice president of research and development for security firm @Stake, which counts Microsoft as a client. "It is definitely in the multi-month category because of how many versions of the operating system and the big applications that they had to test."

The flaws exist in Microsoft's implementation of a basic networking protocol known as Abstract Syntax Notation One, or ASN.1. The code is shared by many Windows applications, and the vulnerabilities could let a remote user take control of a computer running a version of Windows that hasn't been patched, according to the advisory posted on Microsoft's Web site. Exploiting the flaw is much easier if the attacker can access a local network, the advisory noted.

Such widespread vulnerabilities are most tempting for the underground coders who create worms such as MSBlast -- also known as Blaster -- and Slammer, both of which took advantage of Windows flaws.

Stephen Toulouse, senior program manager of Microsoft's Security Response Centre, said the fix took so long to create because of the difficulties posed by such a pervasive technology.

"ASN.1 is really an extremely deep... technology in Windows itself," Toulouse said. "This investigation required us to evaluate several different aspects. This is an instance where we really had to do our due diligence."

Yet the complexity of the problem isn't necessarily an adequate reason for the delay.

Another ASN.1 flaw that affected many more companies and involved more research was made public in only five months. Although the decision to disclose information on the flaw was made after such information had already leaked out, many companies had fixes in place or quickly made them available.

That flaw made network devices using version 1 of the Simple Network Management Protocol (SNMP) -- a data language that allows network hardware to communicate over the Internet -- vulnerable to attacks aimed at causing instability, crashes or compromises.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
165 out of 298 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Microsoft Windows 7 Special Report Special Report

How Microsoft can make Windows 7 a success

How Microsoft can make Windows 7 a success

Comment Many businesses have given Vista a wide berth; Microsoft must focus on five areas to make sure Windows 7 doesn't suffer the same fate, argues TechRepublic's Jason Hiner

More Special Reports

Win a Creative Zen X-Fi2 player and accessories

Win a Creative Zen X-Fi2 player and accessories

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters