You are here: silicon.com > Software > Security Strategy

Security Strategy

'Worst ever Windows vulnerability' discoverer finds seven more holes

But no patches from Gates and chums yet

By Munir Kotadia

Published: 11 February 2004 14:40 GMT

EEye, the company that originally discovered a critical Windows bug patched by Microsoft on Tuesday, says it is waiting on fixes for seven more Microsoft bugs - three of them meriting a "high" severity rating.

Microsoft released a patch for Windows on Tuesday that fixed one of the most severe security holes ever found in the operating system. Microsoft said it took more than six months to fix the problem and to make sure the patch was thoroughly tested. During this time, the vulnerabilities could have been exploited by another MSBlast-type attack, allowing a virus to rapidly infect a large number of internet-connected computers, according to security experts.

EEye now says it has reported another seven as-yet-unpatched bugs to Microsoft, some as long as five months ago. The company is listing the report dates and seriousness of the bugs on its website, but will reveal no further information until Microsoft has released fixes.

Two of eEye's most dangerous flaws were reported to Microsoft on 10 September 2003, while the third was brought to the company's attention a month later. According to eEye's website, the fixes are overdue by 94 and 66 days respectively.

EEye is one of many security research organisations reporting vulnerabilities to Microsoft, but is one of the few which allows the public to monitor the progress of its bug reports. Some researchers have been known to release public warnings about specific flaws if they judge a software vendor is taking too long to patch, a practice which vendors have heavily criticised.

According to eEye's website, full details of each vulnerability "will be disclosed to the public at the time a patch is released from the vendor".

Munir Kotadia writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
XenServer and Provisioning Server Escalation Engineer - Citrix Systems Ireland

Design and host advanced training classes quarterly for the Global Escalation and ANG TRM Teams Participate in internal employee facing and external ...

Games Tester/Games Test Engineer/ Games QA Engineer/

Experience required of testing PC, or console games, and familiar with logging bugs, and writing and following test cases Good technical knowledge of ...

Technical Support Specialist

Performing a second or third line support role, you will also liaise closely with the product development teams regarding the product future, ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: