You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft: Yes, there's a flaw in Windows wi-fi...

... but we probably won't fix it until 2007

Tags: flaw, windows, microsoft

By Tom Espiner

Published: 19 January 2006 11:30 GMT

Microsoft has admitted there is a security flaw in the way Windows handles wireless connections but the company has said it may not fix the problem until its next Service Pack is released.

The flaw, within a Windows feature that automatically searches for a wi-fi network to connect to, was made public last Saturday by security researcher Mark Loveless at hacker conference ShmooCon. It can be used by a hacker to gain access to files on a victim's laptop, Loveless claimed.

Microsoft said it had finished investigating this claim and had found there is scope for users to be compromised. However, it does not plan to rush out a fix.

Microsoft said in a statement: "Due to the design of this feature, the most appropriate method for adjusting the default behaviour is in a future Service Pack or update rollup."

On Tuesday, the software behemoth revealed it was not planning to release the next Service Pack for XP, called XP SP3, until the second half of 2007.

Microsoft recommended on Wednesday that customers enable a firewall, get software updates, and install antivirus software. Customers who believe they may have been affected can contact Microsoft Product Support Services via its website.

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Web Applications Vulnerability Tester

Useful: CISSP, CEH certified ethical hacker), PCI, HTML, Java, .Net, SQL.Net, VB.Net, C#, C++, Oracle, snort, nessus, fortify, Unix, Linux, Windows. ...

SC Cleared Engineer - Gloucester - EPOS - DESKTOP

SC Cleared Engineer - Gloucester - EPOS - DESKTOP ESSENTIAL SKILLS Valid UK Driving Licence Proven experience as a hardware engineer in Desktop, ...

First Line Support / IT Helpdesk Analyst

The 1st line team will log diagnose and where possible fix these customer issues. Ensure that customer Service Level Agreements and key performance ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: