- Recommend:
- 0 Comments
Patches Issued for Java, Windows Flaws
Microsoft urges users to plug hole in its VM for Java, Windows remote terminal functions.
Microsoft is warning of two software flaws that could let an attacker take control of PCs running its Windows operating systems. All Windows users should patch their software to correct the flaws, which Microsoft described as critical in a notice this week.
The flaws lie in Microsoft's virtual machine (VM) software for running Java applications on Windows PCs. All versions of the VM, including the latest 5.0.3805, are affected, Microsoft said in security bulletin MS02-052.
The first flaw lies in a feature that allows Java applications to connect to databases, the second in a function that supports the use of XML (Extensible Markup Language) by Java applications, Microsoft said.
To exploit the flaws, an attacker would have to send the user an e-mail in HTML format or lure a user to a specially crafted Web site. An attacker could take virtually any desired action on a user's system after a successful attack, according to Microsoft.
The VM is a standard part of most versions of Windows and is delivered with the Internet Explorer Web browser. It has also been available as a separate download, Microsoft said. Users can check if they have the VM installed by accessing the command prompt and entering "jview." The VM is installed if a program starts.
Other Flaws Noted
On Wednesday Microsoft also disclosed a third, less serious flaw in the database support functions of its VM. Exploiting this flaw, classified "low" on Microsoft's severity rating, would at least crash Internet Explorer, but could allow an attacker to run code on the user's computer, Microsoft said.
This is not the first time that Microsoft has had to alert users to a flaw in its VM. The software maker issued a "critical" alert in March because of a flaw that could let an attacker put a tap on a user's Web browser.
In a separate security bulletin Wednesday, Microsoft warned of two flaws in a feature that supports remote terminal connections to PCs running Windows 2000 and Windows XP. These "moderate" flaws affect users of Terminal Services and Remote Desktop. More information can be found in security bulletin MS02-151.
Vendor Chided
Thor Larholm, a security researcher based in Denmark working for PivX Solutions LLC, said Microsoft's VM is "fundamentally insecure."
"Microsoft's virtual machine overall is fundamentally insecure," Larholm said. "Java usually enforces a sandboxing model so you can run code in a safe manner. But Microsoft's VM allows any programmer to escape that secure model."
Users seeking an alternative to Microsoft's VM could choose to install Sun's Java VM for Windows systems. Sun is the inventor of Java. Larholm, who is also a Java programmer, said he likes the Sun Java virtual machine (JVM), but that it may have its own security bugs.
"The Sun JVM is not as widely used at Microsoft's and I don't know if there are any vulnerabilities in it," Larholm said. "There is more incentive to look for vulnerabilities in Microsoft's software because it is so widely used."
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Bugs and Fixes: Medicine for IE, Outlook, and Windows
- ActiveX Overhaul in Microsoft Patch Batch
- Windows Phone 7.5 SMS Vulnerability Can Disable Messaging
- Microsoft Discusses Windows 8 Tweaks After User Feedback
- Patch Tuesday Fixes Critical Bluetooth Flaw in Windows 7
- Patch Tuesday Fixes Dangerous Flaws with Exploits Imminent
- Windows 8 Will Sport a Revamped Explorer
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.

















