- Recommend:
- 0 Comments
Microsoft Patches Eight Software Holes
Security holes, two of which are serious, involve the virtual machine used to run Java apps on Windows.
A serious security flaw in Microsoft's virtual machine found on most Windows PCs could allow an attacker to take over a user's system, Microsoft warned late Wednesday. A fixed version of the software is available.
Microsoft's VM is used for running Java applications on Windows PCs and comes with most Windows and Internet Explorer versions. All builds up to and including build 5.0.3805 are affected by eight security flaws, six of which pose a "low" or "moderate" risk to users, Microsoft said in security bulletin MS02-069.
Two vulnerabilities, however, are serious. Exploiting a "critical" flaw in a security feature of the VM could allow an attacker to gain control over a user's system, while another "important" flaw could be exploited to trick the VM into giving an attacker read access to files on a user's PC and network drives, Microsoft said.
Rating System
Under Microsoft's security rating system, changed last month, critical vulnerabilities are those that could be exploited to allow malicious Internet worms to spread without user action. Important are those vulnerabilities that could expose user data or threaten system resources.
An attacker could exploit the VM flaws by luring a user to an especially coded Web page or sending that page via HTML e-mail, Microsoft said. The Redmond, Washington, company urges users to upgrade to VM build 3809, which is available from the Windows Update Web site.
Users can check if and what version of Microsoft's VM is installed by opening a command box and entering "jview." VM is installed when a program runs. The version number appears in the topmost line.
Windows Warnings
Also on Wednesday, Microsoft issued two other security bulletins warning of issues with various Windows versions.
Deemed "important" is a privilege elevation vulnerability in Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP. A malicious user could gain administrative privileges on a system by exploiting the flaw which lies in a Windows function, Microsoft said in security bulletin MS02-071.
A third Microsoft bulletin, MS02-070, details a "moderate" risk vulnerability in Windows 2000 and Windows XP without Service Pack 1 installed. An attacker could change group policy data received by client systems by silently disabling the signing of Server Message Block packets, Microsoft said.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Stellar Tech Deals
Don't miss out on great deals from around the web.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Windows Phone 7.5 SMS Vulnerability Can Disable Messaging
- Patch Tuesday Fixes Critical Bluetooth Flaw in Windows 7
- Microsoft Discusses Windows 8 Tweaks After User Feedback
- Windows XP: Pros and Cons of Not Upgrading
- Patch Tuesday Fixes Dangerous Flaws with Exploits Imminent
- Microsoft to Windows XP: Please Die, Already
- Microsoft Warns of New Windows Vulnerability
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.




















