| Microsoft Corp. posted a "critical" security patch for Windows XP today, and a digital security outfit called eEye claimed credit for finding the "major vulnerabilities" in the new OS that allows an attacker to gain system level access.
Redmond, Wash.-based Microsoft posted on its site that the impact of the vulnerability is to allow someone to "run code of attacker's choice." Investors didn't like the news, and Microsoft stock finished the day Thursday down $2.73 to $66.76.
Furthermore, Microsoft said that "customers using Windows 98, 98SE or ME should also apply the patch if the Universal Plug and Play service is installed and running." The patch can be found here.
Aliso Viejo, Calif.-based eEye Digital Security put out a press release "announcing the discovery of major security vulnerabilities in Microsoft's UPNP (Universal Plug and Play) Service.
VistaKnowledge.com Microsoft Reissues Critical Security Fix For :: Microsoft has reissued a critical patch for the Bluetooth stack in Windows XP, Recent Posts. Under the Hood, Windows 7 Is Vistas Twin. 11-12-2008 http://www.vistaknowledge.com/vista-news/microsoft-reissues-criticurity-fix-for-windows-xpHOME |
The company said that Windows XP, by default, ships with a UPNP Service that can be used to detect and integrate with UPNP-aware devices.
eEye said it alerted Microsoft's security team immediately upon discovery of the vulnerability and has worked closely with Microsoft on the patch and on alerting administrators worldwide.
Microsoft Releases Patch For Critical Vulnerability:: You can download it manually at Microsofts website or via Windows Update. Related Posts: web browser web browsers windows windows vista windows xp xnview http://www.ajuaonline.com/2008/10/23/microsoft-releases-patch-for-critical-vulnerabilityHOME | firewall, and Microsoft Windows XP Service Pack 2 news and reviews on CNET:: and trusted editor and user reviews related to firewall, and Microsoft Windows XP Service Pack 2. News. Microsoft posts critical configuration patch http://www.cnet.com/topic/firewall/microsoft-windows-xp-service-pack-2.htmlHOME |
eEye said it has discovered three vulnerabilities within Microsoft's UPNP implementation: a remotely exploitable buffer overflow that allows an attacker to gain system level access to any default installation of Windows XP, a Denial of Service (DoS) attack, and a Distributed Denial of Service (DDoS) attack.
The most serious of the three Windows XP vulnerabilities is the remotely exploitable buffer overflow, eEye said. It is possible for an attacker to write custom exploit code that will allow them to execute commands with system level access, the highest level of access within Windows XP.
Today @ PC World Patch Tuesday: Microsoft Fixes Critical Windows :: Patch Tuesday again today and Microsoft issued 10 security updates, fixing critical vulnerabilities in its Windows and for Windows XP Service Pack 1, http://blogs.pcworld.com/staffblog/archives/002919.htmlHOME | Microsofts Critical Bluetooth Patch Didnt Work on XP - CSO Online :: Microsoft has re-issued a critical Bluetooth security patch, saying it didnt initially work on Windows XP. Partners. Latest Posts More blogs. Lohrmann http://www.csoonline.com/article/404413/Microsoft_s_Critical_Blueh_Patch_Didn_t_Work_on_XPHOME |
The other two vulnerabilities are types of denial of service attacks. The first is a straightforward denial of service attack, which allows an attacker to remotely crash any Windows XP system. The crash will require users to power down their machines and start them up again before the system will function.
The second denial of service attack is a distributed denial of service attack. This vulnerability allows attackers to remotely command many Windows XP systems at once in an effort to make them flood/attack a single host.
Privately held eEye Digital Security is a developer of high-end network security products, including Retina, its flagship network vulnerability scanner.
New Security Breach Threatens Net
IBM's Quantum Computer Breakthrough |