On CNET: With Chrome, Google reignites OS war
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Feb 8, 2006 4:50:00 AM

Microsoft on Tuesday warned of two security issues that could put some Windows users at risk of attack and said it is investigating a third possible vulnerability.

One security problem is reminiscent of the recent high-profile security woes that affected Windows. It is related to how aging versions of Internet Explorer handle malformed Windows Meta File images on the Windows Millennium Edition and Windows 2000 operating systems.

The flaw exists only in IE 5.01 with Service Pack 4 on Windows 2000 and IE 5.5 with Service Pack 2 on Windows ME, Microsoft said in a security advisory. Users could be attacked simply by viewing a malicious image on a Web site, in an e-mail or in an image viewer, Microsoft said.

"An attacker who successfully exploited this vulnerability could take complete control of the affected system," Microsoft said in its advisory.

Though the WMF vulnerability may appear similar to previous flaws related to WMF that plagued Windows, the issue is different, Microsoft said. Last month the software maker rushed out a fix for a WMF rendering flaw that was being exploited to install spyware on the computers of unwitting Windows users.

To remedy this new WMF problem, Microsoft recommends users upgrade to IE6 with Service Pack 1 and said it may issue a security patch.

In a second security advisory, Microsoft warned of a problem with overly permissive access controls in Windows XP and Windows Server 2003. The problem exists only in versions that do not have the latest service packs installed, the company said.

The access control issue could be exploited by a user with low privileges to run programs and commands that normally require a higher privilege level, Microsoft said. The software maker suggests installing Service Pack 2 on Windows XP or Service Pack 1 on Windows Server 2003 to limit exposure, or manually changing access controls on the four affected Windows components.

In addition to the security advisories, a Microsoft representative on Tuesday said the company is investigating a potential vulnerability in its HTML Help Workshop, a part of the HTML Help Software Development Kit version 1.4.

Attack code that takes advantage of the flaw is publicly available. A successful attack could give an attacker full control over a vulnerable computer, security monitoring company Secunia said in an alert. However, the scope is limited because the vulnerable software is used only by software developers and is not part of Windows, according to Microsoft.

"Microsoft's initial investigation has revealed that customers who have not installed the HTML Help SDK on their systems are not impacted by this report," the representative said.

Microsoft's next "patch Tuesday" is on Feb. 14. The company on Thursday is expected to release some details on what software fixes it will deliver.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 53 Talkback(s)
Give us a break on this one.....oh please...
Wow. lets be honest here, anyone so poorly updated as to be running a configuration as outdated as that is probably still opening attachments from unknown emails and installing spyware on their system... (Read the rest)
Posted by: Cayble Posted on: 02/09/06 You are currently: a Guest | | Terms of Use
Wow more windows problems ,  I'm Ye, the MS SHILL . | 02/08/06
Oh snap  I'm Ye, the MS SHILL . | 02/08/06
Who runs crap that old?  Suicida| | 02/08/06
grandmas..  Jeff Spicoli | 02/08/06
Older expensive CNC equipment  pickle@... | 02/08/06
Give us a break on this one.....oh please...  Cayble | 02/09/06
Preemptive Strike  CattleProd | 02/08/06
What insanity !  realitycheck101 | 02/08/06
Where you been latelyYEARIGHT?  zmud | 02/08/06
WIN32 needs to run as a virtualized subsystem  ITTech001 | 02/08/06
It's the user, not necessarily the OS.  numbers987654321 | 02/08/06
Wooooooooooo  I'm Ye, the MS SHILL . | 02/08/06
I agree, Its been said many ? many times that the average Windows user.....  Can you hear me | 02/08/06
Thank you for the link  Still Lynn | 02/08/06
Underestimate the loss of personal files  NonZealot | 02/08/06
Exactly  Suicida| | 02/08/06
Question Lynn  I'm Ye, the MS SHILL . | 02/08/06
Joris chumming the waters again.  IT Scion | 02/08/06
Just a funny thought ,  I'm Ye, the MS SHILL . | 02/08/06
So true.  IT Scion | 02/08/06
Not another OS holy war a-brewing...?  JonathonDoe | 02/08/06
When is the human race going to grow up?  Me_too | 02/08/06
ZDNet is anti-Microsoft  NonZealot | 02/08/06
2 years? Try 7!  Delusional | 02/08/06
But others here say it's pro-Microsoft  Boot_Agnostic | 02/08/06
That was kind of my point  NonZealot | 02/08/06
Well, I have read here that  John Zern | 02/08/06
how could you not know if it was true?  Shelendrea | 02/08/06
Awwww shucks, Zealot..  Jeff Spicoli | 02/08/06
Then explain...  ju1ce | 02/08/06
To play devils advocate here...  toadlife | 02/08/06
Issues? Why do I have to pay for protection from issues they created?  ordaj@... | 02/08/06
You pay for your service packs?  NonZealot | 02/08/06
Windows OneCare? I don't think so  ordaj@... | 02/08/06
Bzzt, try again  NonZealot | 02/08/06
you can fix these problems....  JoeMama_z | 02/08/06
Microsoft warns of new Windows security issues  Loverock Davidson | 02/08/06
Yep...serious...  Cardinal_Bill | 02/08/06
Very serious  Loverock Davidson | 02/08/06
You truely are an idiot.  Cardinal_Bill | 02/08/06
Anti-virus protects you from OS?  NonZealot | 02/08/06
Lovecrock you're an a$$  I'm Ye, the MS SHILL . | 02/08/06
I wouldn't say everyone is  Michael Kelly | 02/08/06
FRET NOT MY MICROSHILLS!!!  Jeff Spicoli | 02/08/06
To quote a famous man...  Confused by religion | 02/08/06
Love Dr. Neuman..  Jeff Spicoli | 02/08/06
I Read It  wheezel | 02/08/06
.....zzzzzZZZZZzzzzz....  Mr. Roboto | 02/08/06
Windows is faster and prettier  duclod | 02/08/06
Why not ?  Suicida| | 02/08/06
Bitty And Mike Cox Are Locked Away In An Underground Bunker  itanalyst | 02/08/06
Message has been deleted.  Jeff Spicoli | 02/08/06
I blame Sun for the problem  Boot_Agnostic | 02/08/06

What do you think?

Smartphones

  • Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they’re arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
  • From Our Sponsors
  • Press and be impressed.
  • Tap into streaming videos or view files on the go. Feel life with the powerful touch of the BlackBerry® Storm™. Learn more
advertisement
Click Here