Quantcast

Microsoft Issues Windows Bug Warning

Off-schedule bug fix addresses denial-of-service vulnerability in Windows 2000, XP.

Jaikumar Vijayan, Computerworld

  • 0 Yes
  • 0 No

Microsoft has issued an out-of-cycle advisory warning users about a newly disclosed denial-of-service vulnerability in Windows 2000 Service Pack 4 and Windows XP Service Pack 1.

The company was prompted to issue the advisory because of reports about proof-of-concept code that seeks to exploit the flaw, the company said in its advisory.

Advisory Explains

"Microsoft is concerned that this new report of a vulnerability in Windows 2000 Service Pack 4 and Windows XP Service Pack 1 was not disclosed responsibly, potentially putting computer users at risk," Microsoft says in its advisory.

The advisory adds that Microsoft is currently not aware of any attacks that have resulted from the exploit code. However, "Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary" the company said.

In the meantime, companies need to ensure that their systems are properly updated and have all recommended patches installed, Microsoft said.

The advisory states that "on Windows XP Service Pack 1, an attacker must have valid log-on credentials to try to exploit this vulnerability. The vulnerability could not be exploited remotely by anonymous users. However, the affected component is available remotely to users who have standard user accounts. Customers who have installed Windows XP Service Pack 2 are not affected by this vulnerability. Additionally, customers running Windows Server 2003 and Windows Server 2003 Service Pack 1 are not affected by this vulnerability."

Bug-Fix Process

Since Microsoft moved to a monthly patch release cycle about two years ago, the company has rarely issued out-of-cycle patches such as the one announced Thursday.

The company has been working with security researchers and bug hunters to agree on a practice by which vulnerabilities are reported directly to the software vendor, giving it a chance to fix flaws before details are released publicly.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

"Microsoft Issues Windows Bug Warning" Comments

Related Windows Articles

  • CDW Virtualization Center What is Virtualization and how can it help you save money? Click here to find out.
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)