You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft patches new Windows flaw

Are you keeping up?

By Ian Fried

Published: 12 May 2004 08:35 GMT

Microsoft has detailed a new vulnerability in Windows XP and Windows Server 2003 that could enable an attacker to remotely execute malicious code.

The software maker described the problem as "important," its second-highest rating for such problems. Antivirus software maker Symantec, meanwhile, characterised the vulnerability as "high risk," citing the impact that there could be if the vulnerability was successfully exploited.

The flaw exists in the way Windows' Help and Support Centre validates information that is sent to it. The software maker released a patch for the vulnerability and urged customers to "install the update at the earliest opportunity". The patch is posted to the company's security website, as is a bulletin outlining the flaw.

The bulletin was released as part of Microsoft's regularly scheduled monthly security update, according to Stephen Toulouse, a security program manager in the Microsoft Security Response Centre. As for the rating level, Toulouse said Microsoft typically only deems vulnerabilities "critical" - the highest level - if they can be exploited without the user taking any action.

The announcement of the flaw comes as Microsoft works to battle the outbreak of the Sasser worm and its variants. The software giant has been touting the arrest of a German teenager believed responsible for Sasser and other recent infections.

However, unlike Sasser, the latest vulnerability cannot be exploited simply through an email worm. According to Symantec and Microsoft, there are a number of steps the user would need to take in order for their system to be compromised. Most likely, an attacker would have to host a website with a page designed to exploit the vulnerability and convince a user with an unpatched system to visit the site and perform several actions.

Microsoft warned of the vulnerability that led to Sasser in a bulletin last month.

The patch released on Tuesday by Microsoft to fix the new flaw also makes two other changes designed to make Windows more secure. First, Microsoft removed a feature in Windows XP that gave users the option to upgrade a DVD decoder, in a move designed to prevent malicious exploitation of the feature.

Second, Microsoft eliminated a feature in the Help and Support Centre that sometimes prompts people to send out information on their system's hardware after they run the "Found new hardware" wizard. Now, instead of being prompted to send their hardware information, users will now get an error message at the end of installing new hardware.

Ina Fried writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Infrastructure Support -Software Packaging Technician- Investment Bank

Sysprep Symantec Ghost PXE - Excellent understanding of Software Packaging tools Altriris Wise Package Studio MS Windows Installer editing using ...

IT Support Team Leader - 1st Line,Windows XP,Novell NetWare,MS Office

IT Support Team Leader - 1st Line Support, Windows XP, Novell NetWare, MS Office 2003/2007University College Birmingham is seeking to recruit an ...

Trainee IT Support Analyst (MS Office 2003, Windows XP, Hardware)

Trainee IT Support Analyst (MS Office 2003, Windows XP, Hardware)Trainee IT Support Analyst Required by a high profile international professional ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: