
'Um... You know how we said there'd be no more patches? Well there's just this one... And it's quite important... '
By Robert Lemos
Published: 17 December 2004 15:20 GMT
Microsoft released a "critical" fix on Thursday for a security issue left unresolved by the Windows XP Service Pack 2.
Gary Schare, director of product management for Windows, said the configuration change closed a hole in the Windows firewall settings that could open up PCs to attack if the machines had been set to share files or a printer with the local network.
"The changes we made in Service Pack 2 were better than before, but they could be narrowed even further," he said. "We told people [in September] that we would issue a software update and now we have."
The hole could allow anyone to access a PC that has its file sharing exceptions set up in the Windows XP SP2 firewall. The problem affects only those who use dialling software to connect to the Internet, Microsoft indicated in a Knowledge Base article on its website.
Microsoft did not classify the configuration issue as a software vulnerability and so did not distribute the configuration update with the patches it released earlier this week, Schare said. In fact, the security group did not handle the issue; the Windows product group did.
"We didn't do as good a job as we intended getting this out," he said. "This fell between the teeth. The security team said it wasn't a vulnerability, so we don't handle it, and the product people said they are not used to meeting the monthly update schedule."
Windows XP users who use Windows update will automatically download the configuration changes.
Wish i could say i was surprised.......
Anonymous
XP Patch is supposed to make things better right? ...
Barry Haeger
'Patch' implies hole, which in turn implies a lack...
Rich White
My system also became unstable after installing th...
Anonymous
"Fell between the teeth" - that's a new phrase to ...
Anonymous
Linux Redhat Systems Administrator - Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). Fantastic opportunity ...
To apply online please go to www.farn-ct.ac.uk or call our 24 hour recruitment line on 01252 407020 quoting the post reference to receive an ...
You will need to maintain software licences and hardware databases, and also re-image PCs. My client based in South Yorkshire, urgently requires 6 ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...