Sunday, October 26, 2014
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
Panasonic to Offload Sanyo's North America TV Business
Google's Pichai to Become Head of Product at Google: report
Internet Explorer 11 Toolkit Allows Enterprise Admins "Spy" On Their Employees
FCC Says Airwave Auction To Delay Until 2016
HP Broadens Moonshot Portfolio With Intel-powered Models
Microsoft To Keep Nokia Brand For Low-end Smartphones
LG Introduces Its First Octa-Core Application Processor
Cloud and Surface 3 Drive Microsoft's Revenue
Active Discussions
Copied dvd's say blank in computer only
How to generate lots of different CDs quickly
Yamaha CRW-F1UX
help questions structure DVDR
Made video, won't play back easily
Questions durability monitor LCD
Questions fungus CD/DVD Media, Some expert engineer in optical media can help me?
CD, DVD and Blu-ray burning for Android in development
 Home > News > General Computing > Microso...
Last 7 Days News : SU MO TU WE TH FR SA All News

Monday, April 25, 2005
Microsoft Confirms Dangerous Vulnerability in Windows 2000


In atypical fashion, Microsoft program manager Stephen Toulouse remarked on the issue on the Microsoft Security Response Center blog.

Microsoft has confirmed reports that a potentially dangerous security hole exists in Windows 2000 systems and that users could be at risk for attack.

Details about the vulnerability were first reported by Israel-based GreyMagic, which posted details and relevant code on its Web site.

The company issued an advisory warning users that a malicious hacker could use Windows Explorer to navigate through the Windows file system of an unsuspecting user.

Response Call
In atypical fashion, Microsoft program manager Stephen Toulouse remarked on the issue on the Microsoft Security Response Center blog . Usually, Microsoft managers do not comment on specific security issues, especially on a blog.

Toulouse noted that the issue involves the Windows shell, and the company's initial investigation found that significant user interaction would be required for an attacker to exploit the vulnerability.

Microsoft has confirmed that Windows XP , Windows XP SP2 and Windows Server 2003 are not affected by the bug.

Manager Insight "We're also looking into reports of proof of concept code that has been made public that could seek to exploit this reported vulnerability," Toulouse wrote. "On that note, we're not currently aware of any customer impact as a result or an attack that seeks to exploit this vulnerability."

Once Microsoft's investigation is complete, it might decide to provide a fix through an out-of-cycle security update, he added.

In the meantime, he recommended that users block Server Message Block communications at the firewall to protect themselves from possible attack.

Critical Eye
Microsoft has criticized GreyMagic for publishing proof-of-concept code with its advisory, a move that is more true to form for the company, said Secunia security researcher Thomas Kristensen.

"Microsoft very much believes that code should not be made available and freely disclosed in the security community," he said.

As the debate rages over whether to disclose code, the fact remains that Microsoft patches for vulnerabilities like the Windows 2000 flaw are closely watched, Kristensen noted.

"We would hope that Microsoft would release a patch for this quickly," he said. "Microsoft vulnerabilities affect too many people to go unpatched for too long."

From TopTech News



Previous
Next
TiVo looks for an edge        All News        Clever design gives AMD edge over Intel
Sony Europe Announces First PC With DSD, ASIO 2.1 and Blu-Ray Disc     General Computing News      The Death of illegal P2P?

Source Link Get RSS feed Easy Print E-Mail this Message

Related News
Microsoft To Keep Nokia Brand For Low-end Smartphones
Cloud and Surface 3 Drive Microsoft's Revenue
Microsoft Releases New Kinect SDK And Adapter Kit
Windows 10 To Offer Enhanced Security and Identity Protection
Microsoft Is Rolling Out First New Windows 10 Preview Build
Microsoft And Dell Puts Azure In A Box
Microsoft To Launch A Wearable Device Soon
Microsoft CEO Apologizes For Suggesting Women not Ask for Raises
Microsoft says Samsung owes Millions in unpaid Patent Royalties
DirectX 12 Coming On Windows 10
Internet Explorer and the Windows 10 Preview
Microsoft Previews Windows 10

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2014 - All rights reserved -
Privacy policy - Contact Us .