You are here: silicon.com > Software > Security Strategy

Security Strategy

Windows 2000 open to attack

eEye spots a wormhole...

Tags: windows 2000, windows, microsoft

By Dawn Kawamoto

Published: 4 August 2005 08:30 BST

A serious flaw has been discovered in a core component of Windows 2000, with no possible workaround until it gets fixed, a security company said.

The vulnerability in Microsoft's operating system could enable remote intruders to enter a PC via its internet protocol address, Marc Maiffret, chief hacking officer at eEye Digital Security, said on Wednesday. As no action on the part of the computer user is required, the flaw could easily be exploited to create a worm attack, he noted.

What may be particularly problematic with this unpatched security hole is that a workaround is unlikely, he said.

"You can't turn this [vulnerable] component off," Maiffret said. "It's always on. You can't disable it. You can't uninstall."

eEye declined to give more details on the flaw or the Windows 2000 component in question. As part of company policy, it does not release technical details of the vulnerabilities it finds until the software's maker has released either a patch or an advisory.

A Microsoft representative said the software giant will issue a comment once it has had a chance to review the eEye advisory, which has yet to be posted on the security company's website.

The vulnerabilities affect Windows 2000 but Maiffret noted eEye is still conducting tests, and he anticipates other versions of Microsoft's OS are likely to be affected.

For Microsoft, this marks the second eEye advisory it's received this week. On Monday, eEye notified the software giant it had found critical vulnerabilities in Internet Explorer.

The IE vulnerabilities could allow malicious attackers to launch a remote buffer overflow attack should users click on a malicious website link.

The flaw, which is rated as "high" risk, affects IE, Windows XP and SP1, Windows 2003 and Windows 2000.

Microsoft confirmed it received the eEye advisory regarding IE through its standard vulnerability reporting system.

A Microsoft representative said: "We are investigating the report and will take appropriate action to help protect customers as part of our normal security response process." Microsoft issues a monthly bulletin of patches and also has a programme of security advisories with workarounds for unpatched, reported flaws.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Integration Engineer

If you want to put yourself forward to join us, click on the link below which will take you through to our website where you can build your profile ...

Website Content Manager - Mental Health Care

Website Content Manager - Mental Health Care Department of Psychology/Computing and Knowledge Management This is a unique opportunity for someone who ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: