Microsoft issues Critical Security Flaw Warning

Discuss anything not covered in another forum (life, the universe etc.)... Please keep it PG-13 and avoid spam.
Post Reply
User avatar
minir
Posts: 27941
Joined: Sat Aug 19, 2000 12:00 am
Location: Canada

Microsoft issues Critical Security Flaw Warning

Post by minir »

Saw this Listed today
================



By TED BRIDIS - Associated Press



WASHINGTON (AP) -- Microsoft Corp. warned customers Tuesday about unusually serious security problems with its Windows software that could let hackers quietly break into their computers to steal files, delete data or eavesdrop on sensitive information.

Microsoft, which learned about the flaws more than six months ago from researchers, said the only protective solution was to apply a repairing patch it offered on its Web site. It assessed the threat to computer users as "critical," its highest rating.

A Microsoft security executive, Stephen Toulouse, said the flawed software was "an extremely deep and pervasive technology in Windows," and urged customers to apply the patch immediately.

The disclosure comes just weeks before Microsoft Chairman Bill Gates delivers a keynote speech in San Francisco at one of the industry's most important security trade conferences. Microsoft has struggled in recent months against a tide of renewed criticism about security risks in its software, the engine for computers in most of the world's governments, corporations and homes.

"This is one of the most serious Microsoft vulnerabilities ever released," said Marc Maiffret of eEye Digital Security Inc. of Aliso Viejo, Calif., which discovered the new Windows flaws. "The breadth of systems affected is probably the largest ever. This is something that will let you get into Internet servers, internal networks, pretty much any system."

Maiffret said some computer systems that control critically important power or water utilities were vulnerable.

Maiffret predicted hackers will try to unleash a damaging Internet infection within weeks. Unlike earlier vulnerabilities that spawned such attacks, hackers can exploit the newly disclosed flaws to break into susceptible computers using dozens of methods, making any defense far more difficult.

"The race will be on," agreed Marcus Sachs, a former White House adviser on cybersecurity.

Researchers at eEye discovered the problems last July and agreed to keep quiet about them until Microsoft could fix them. Maiffret complained that the delay between eEye's discovery and Tuesday's public disclosure by Microsoft was "just totally unacceptable" because Windows users were broadly vulnerable during the period.

Toulouse said Microsoft took months because it wanted to ensure that a single repairing patch solved any related problems. "We really took the steps to make sure our investigation was as broad and deep as possible," he said.

Maiffret and Microsoft said they were unaware anyone had yet attacked Windows computers using the technique, although eEye had successfully tested the method to break into its own computers.

Microsoft's disclosure occur just days before a presidential advisory council submits recommendations to the White House about ways technology companies should respond to major software vulnerabilities that could affect national security. The 54-page report, obtained by The Associated Press, cautions that "long delays in remediation can result in prolonged risk to end users."

The problems affected a technology in the newest versions of Windows known as "abstract syntax notation," a way to share data across different computers. Some of Microsoft's built-in security features -- such as its Kerberos cryptography system -- rely on the flawed software.

Microsoft urged consumers to apply the repairing patch immediately if they were using Windows NT, Windows 2000 or Windows XP versions of its software, or its Windows NT Server, Server 2000 and Server 2003 software commonly found in corporations.

http://v4.windowsupdate.microsoft.com/en/default.asp

-----


regards

minir
Brk
SG VIP
Posts: 29518
Joined: Sun Dec 09, 2001 12:00 pm

Post by Brk »

I don't see the patch listed at Windows Update, but here it is over at TechNet:

http://www.microsoft.com/technet/treevi ... 04-007.asp
qball15j
Senior Member
Posts: 3619
Joined: Mon Nov 26, 2001 9:28 pm

Post by qball15j »

I got it from windows update last night. (requires restart, which I haven't done yet here on my main machine) ;)
User avatar
minir
Posts: 27941
Joined: Sat Aug 19, 2000 12:00 am
Location: Canada

Post by minir »

Hi Burke



I went to Windows Update & Downloaded it their?


Anyway Thanks for the New Site its appreciated :)


regards

minir
Brk
SG VIP
Posts: 29518
Joined: Sun Dec 09, 2001 12:00 pm

Post by Brk »

Hmm. Never shows up in my Windows Update...
User avatar
minir
Posts: 27941
Joined: Sat Aug 19, 2000 12:00 am
Location: Canada

Post by minir »

Morning qball15j & Burke


qball15j

I had to Flush Twice after i downloaded. The first time my modem didn't show up, so i Flushed again and Voilà!

---


Burke

I have no answer for you on that issue...Sorry

--

Thanks Fellas, Have a Great day :)


regards

minir
User avatar
binksfan
Posts: 1275
Joined: Fri Jul 06, 2001 4:50 pm
Location: Orange Co., Calif.

Post by binksfan »

Mine just showed up this A.M. on main (XP) machine and 2nd (2K) machine. Thanx for info minir!
ß¡ñk§ƒ@ñ

"Okay! Who stole the cork outta my lunch?":irate:
User avatar
AMPLIFRIER
Posts: 1641
Joined: Fri Jun 22, 2001 12:20 am
Location: 127.0.0.1

Post by AMPLIFRIER »

Originally posted by Burke
Hmm. Never shows up in my Windows Update...


are you running auto updates?

AMP
Gigabyte ga-7n400 pro nForce2 mobo, Athlon XP3200, thermalright slk900, 1 gig corsair pc3200 cas2, radeon 9800pro, SB Audigy 2 ZS
case= yeong yang YY-B0221 server cube,550 watt Antec true power,1 wd raptor 74 gig,1 34gig raptor (page) 2 wd 120gig se's raid 1, 1 120gig se. WIN xp Pro, Dual display samsung syncmaster 1100df 21in(Primary) Samsung syncmaster 955df 19in (secondary)".
Brk
SG VIP
Posts: 29518
Joined: Sun Dec 09, 2001 12:00 pm

Post by Brk »

Originally posted by AMPLIFRIER
are you running auto updates?

AMP
Oh HELL no.

I check Windows Update once a week, though.
User avatar
Spicer
Senior Member
Posts: 2313
Joined: Wed Apr 09, 2003 12:18 pm
Location: Canada

Thanks There Minir...

Post by Spicer »

Got It Down... :) Spice
"Accept The Challenges, So That You May Feel The Exhilaration Of Victory".....Patton
User avatar
wee96
Posts: 9253
Joined: Sun May 13, 2001 12:00 pm
Location: Michigan

Post by wee96 »

Thanks for the heads up minir, it seems like no matter how many patches M$ seems to put out, theres always flaws to be found, its a never ending battle....
User avatar
minir
Posts: 27941
Joined: Sat Aug 19, 2000 12:00 am
Location: Canada

Post by minir »

Originally posted by wee96
Thanks for the heads up minir, it seems like no matter how many patches M$ seems to put out, theres always flaws to be found, its a never ending battle....



--------

Hi binksfan, AMPLIFRIER, Spicer & wee


wee
Now you know how God must feel. :eek: :rotfl:


Your Welcome Fellas, Have a Wonderful day :)


regards

minir
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

Spent a portion of the day on this. Still more to go. :eek:
Post Reply