ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Windows flaw threatens PC services

Published: 29 Aug 2002 07:32 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft said on Wednesday that a critical flaw in most versions of the company's Windows operating system could allow malicious attackers to corrupt the digital certificates that PCs use to connect to network services.

The vulnerability can be exploited via a special coded ActiveX inserted into hypertext markup language (HTML), the lingua franca of the Web. To fall victim to attack, a PC user would have to browse a Web site, or open an HTML email, specifically set up to take advantage of the vulnerability.

"(The flaw) could enable a Web page, through an extremely complex process, to invoke the (ActiveX) control in a way that would delete certificates on a user's system," Microsoft warned in an advisory released late on Wednesday.

Such digital certificates are used to hold encryption keys used in email, the encrypted files system (ESS) that is shipped with certain versions of Windows, and in the Secure Sockets Layer communications protocol used by many e-commerce Web sites. ESS is shipped in Windows 2000 and Windows XP Professional. While the flaw doesn't allow a malicious vandal to steal the certificates, it does allow the attacker to corrupt the data, rendering it useless to the PC's owner.

Depending on the certificates corrupted, the act would prevent the victim from encrypting and decrypting email, encrypting files and complicate the use of secure Web sites, Microsoft advised. The flaw occurs in the Certificate Enrollment ActiveX Control.

Microsoft suggests that all users of Windows Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000 and Windows XP patch their system immediately.

The latest advisory brings the number of such warnings by the software giant to 48 for the year.


More enterprise IT news in ZDNet UK's Tech Update Channel.

For a weekly round-up of the enterprise IT news, sign up for the Tech Update newsletter.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
23 out of 53 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Linux Systems Administrator - Linux Windows XP, Network Connectivity

Linux Administrator - Linux Redhat Systems Administrator Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). ...

Support Analyst - 2nd line - Windows XP - ITIL - 175-200/day

Windows XP / Blackberry / ITIL / Excel / Poweerpoint / Asset Mgmt. Urgent requirement - 2nd line support role. The client are a global asset ...

DESKTOP SPECIALIST- Financial Traders- London City (40-45k)

Additional knowledge of energy trading applications, application packaging and imaging, and security patch management would be useful as well as ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment