On BNET: Vote: How will Apple blow it?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Dec 17, 2004 1:05:00 AM

Microsoft released a "critical" fix on Thursday for a security issue left unresolved by the Windows XP Service Pack 2.

The configuration change closed a hole in the Windows firewall settings that could open up PCs to attack if the machines had been set to share files or a printer with the local network, said Gary Schare, director of product management for Windows.

"The firewall that we shipped in Service Pack 2 was much better than before, but security could be tightened even further," he said. "We told people (in September) that we would issue a software update and now we have."

The hole could allow anyone to access a PC that has its file sharing exceptions set up in the Windows XP SP2 firewall. The problem affects only those who use dialing software to connect to the Internet, Microsoft indicated in a Knowledge Base article on its Web site.

Microsoft did not classify the configuration issue as a software vulnerability and so did not distribute the configuration update with the patches it released earlier this week, Schare said. In fact, the security group did not handle the issue; the Windows product group did.

"We didn't do as good a job as we intended getting this out," he said. "This fell between the teams. The security team said it wasn't a vulnerability, so we don't handle it, and the product people said they are not used to meeting the monthly update schedule."

Microsoft's Schare said some users complained that the posting of the configuration change wasn't obvious. The company will likely better highlight such bulletins to Windows users in the future.

"We have a process in putting these up," Schare said. "We followed the process, but now we are looking to see if we can do more."

Windows XP users who use Windows update will automatically download the configuration changes.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 24 Talkback(s)
PS
In all fairness to ZD, this was not one of their "knock" MS articles; in general, their rags have not been as anti-MS as in years past...but it still shows up here and there. wink... (Read the rest)
Posted by: Anonynona_z Posted on: 12/20/04 You are currently: a Guest | | Terms of Use
MS firewalls and other jokes on security.  michael-t | 12/16/04
FYI:  Ardian Daka | 12/17/04
Yes but...  Jeff Spicoli | 12/17/04
Slight correction  Chad_z | 12/17/04
Nothing to worry about  Richard Flude | 12/16/04
ZDNET, Why do you keep posting the same old story...  Plain Logic | 12/16/04
Copy paste my lad, Copy paste  Squawkbox | 12/16/04
Message From Ballmer: "Move Along, Nothing To See Here"  itanalyst | 12/17/04
MSFT Process  Chad_z | 12/17/04
rotflmao (NT)  JasonL31 | 12/19/04
The laugh track must be extra, ...  Judas I. | 12/17/04
And Now, A Word From Our Sponsor  itanalyst | 12/17/04
Outstanding.  boabyd | 12/19/04
Ha, Ha !  stewart@... | 12/17/04
I knew "localsubnet" was a bad idea.  JoeMama_z | 12/17/04
SP 2  cardinal33 | 12/17/04
SP 2 was supposed to fix EVERYTHING ?!?!!  Squawkbox | 12/17/04
some practical info please  clancy | 12/17/04
Does it work with SR2  Bruce Swanson | 12/17/04
Microsoft More Useless Everyday...  PhoenixStorm26 | 12/19/04
Not Really A "Fire Wall" - More Like an "Ember Mound" Really (NT)  BanjoPaterson | 12/20/04
Good free firewall  Neil Parks | 12/20/04
A joke...and it's not MS.  Anonynona_z | 12/20/04
PS  Anonynona_z | 12/20/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here