Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft Fixes First Three Windows Flaws Of 2005
TechWeb ^ | January 11, 2005 | Gregg Keizer

Posted on 01/11/2005 1:44:14 PM PST by Eagle9

Microsoft on Tuesday released the year's first three security patches to Windows, including two it called "Critical," but did not patch all the vulnerabilities that have surfaced in the last several months.

"These are exactly what we expected this month, a couple of patches against threats that are 'wormable'," said Mike Murray, the director of research at nCircle, the vulnerability management vendor whose flagship product is IP360.

The first critical flaw is in Windows Server 2003, and in Windows 98, Me, 2000, and XP, including Service Pack 2, the security update that Microsoft rolled out last October. The ancient Windows NT 4.0 is also affected if Internet Explorer 6.0 SP1 has been installed.

A bug in the HTML Help ActiveX control can be exploited by hackers to gain complete control of a compromised PC, said Microsoft, most likely by creating a malicious Web site, then enticing users into viewing that page with e-mail come-ons. Microsoft's HTML Help ActiveX is designed to let Web site designers add site-specific help information to their pages.

The bulletin, dubbed MS05-001, also offered up a long list of possible work-arounds for users who can't patch immediately, but noted that exploits of this vulnerability are already circulating, and urged users to patch pronto.

Another critical vulnerability, spelled out in the MS05-002 bulletin, affects Windows 98, Me, NT, 2000, XP, and Windows Server 2003, and concerns how those operating systems handle cursors, animated cursors, and icons. A determined hacker, said Microsoft, could create a malicious Web site or send e-mail with specially-crafted cursors or icons that would in turn cause the computer to execute the attacker's choice of code or simply crash.

Although the bug has been made public and proof-of-concept code has been spotted on hacker sites, Microsoft claimed that it had no evidence of any actual exploits in the wild. Still, it recommended that users apply the patches immediately.

The third bulletin, labeled MS05-003, is rated by Microsoft as only "Important" in its four-step scale.

"This one was a bit of a surprise," said nCircle's Murray. "Index Server hasn't been a target in the past. It's not enabled by default, and because of that it's almost a waste of time for hackers."

Windows 2000, XP (but not SP2), and Windows Server 2003 are at risk, said Microsoft, because the Indexing Service can be used to gain complete control of a PC. Formerly known as Index Server, the service's original function was to index the content of Internet Information Services (IIS) Web servers, but it's now also used to create indexed catalogs of file systems.

"This could be dangerous in a targeted attack," said Murray directed against a specific company, "but it's not something that will end up as a widespread exploit like MSBlast or Slammer."

Some of the more recent vulnerabilities in Microsoft's products, particularly its Internet Explorer browser, were not included in this month's cycle of patches Murray stepped up to defend Microsoft. "There were some [unpatched] vulnerabilities released publicly, but the [patch] development cycle takes time. There's no way Microsoft has had time to fix these things yet."

Among the disclosed vulnerabilities that weren't patched were a bug in IE's LoadImage API and a long-standing flaw in how IE handles drag-and-dropped objects.

"It takes a month or two to test patches and get them into the products," said Murray. "I expect we'll see [fixes for] these in February."

Tuesday's patches can be obtained through the usual channels: the Windows Update service or direct download from the Microsoft Web site.


TOPICS: Technical
KEYWORDS: computersecurity; exploit; getamac; internetexploiter; lowqualitycrap; microsoft; patch; securityflaw; trojan; update; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-35 next last
They couldn't patch a vulnerability (several) that was discovered in October, 2004. Oh well, maybe March ....
1 posted on 01/11/2005 1:44:15 PM PST by Eagle9
[ Post Reply | Private Reply | View Replies]

To: Eagle9

First three? We're only 11 days into the year! At this rate, we're setting ourselves up for 100 vulnerabilities this year.


2 posted on 01/11/2005 1:48:32 PM PST by antiRepublicrat
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Seems like the discovery of Windows flaws NEVER ends. Will it EVER be safe to put your identity/credit card/bank acct. info on your computer using THIS O/S?


3 posted on 01/11/2005 1:49:00 PM PST by FreeKeys ("...your situation's hopeless and your system's gonna crash!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

It absolutely astonishes me that they presume to promote anti-virus software, when their products need so many patches, you'd think they were making hillbilly blue jeans.


4 posted on 01/11/2005 1:49:26 PM PST by knittnmom
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

They were waiting for download and install when I got home to the very-fast machine; tomorrow, they'll be at work waiting for me to open-up the super-fast machine in my office.

I still think that Apple/Mac/Linux moles work at MS, building this stuff into the Win O/S, on purpose. </saracasm>


5 posted on 01/11/2005 1:50:05 PM PST by 7.62 x 51mm (• veni • vidi • vino • visa • "I came, I saw, I drank wine, I shopped")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

THANKS.


6 posted on 01/11/2005 1:51:16 PM PST by Quix (HAVING A FORM of GODLINESS but DENYING IT'S POWER. 2 TIM 3:5)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9; ShadowAce
Is this one covered yet?

Malicious Trojan infects Windows Media Player

This one may only be a problem if you have installed the latest security fixes from Microsoft incorporated in Service Pack 2.....

7 posted on 01/11/2005 1:51:47 PM PST by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

I don't see any mention of that flaw.


8 posted on 01/11/2005 1:55:27 PM PST by Eagle9
[ Post Reply | Private Reply | To 7 | View Replies]

To: Eagle9

The Drag-and-Drop/Cut-and-Paste issue corrective action was posted long ago. The fix that allows you to use those two functions again in the Internet zone is what has not been released yet.

MS04-038 cumulative Security Update for Internet Explorer

or,

Disable the Drag and Drop or copy and paste files option in the Internet and Intranet Web content zones. For business domains, this can be done in Group policy.


9 posted on 01/11/2005 2:01:55 PM PST by UseYourHead (Beware of the Rinos - McCain, Hagel, Lugar, and Specter)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

BTTT for later


10 posted on 01/11/2005 2:03:56 PM PST by EdReform (Free Republic - helping to keep our country a free republic. Thank you for your financial support!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9
Got a question for you.

I have a lap top and a desktop. we have a dial up modem, DSL is not available at our number yet. But, I can take my laptop down town to an internet cafe adn connect at real high speeds.

All that said, here is my question, how can I down load the windows updates to my CD burner druive insteaqd of my c drive so that I can put it in the desktop and safe a ton of time?

Thanks,
Jake

By the way, where would I find the fixes, updates and patches on my harddrive?

11 posted on 01/11/2005 2:09:02 PM PST by newsgatherer
[ Post Reply | Private Reply | To 1 | View Replies]

To: newsgatherer

Go to the Microsoft Download Center - near the bottom is a list of categories for download - select the Windows (Security and Updates). Save them where you can find them later.

http://www.microsoft.com/downloads


12 posted on 01/11/2005 2:12:17 PM PST by UseYourHead (Beware of the Rinos - McCain, Hagel, Lugar, and Specter)
[ Post Reply | Private Reply | To 11 | View Replies]

To: newsgatherer
How can I down load the windows updates to my CD burner drive instead of my c drive so that I can put it in the desktop and save a ton of time?

By the way, where would I find the fixes, updates and patches on my hard-drive?

I don't know the answer to either question. I think a lot of people would like to know, so I highlighted your questions, in hopes of someone posting an answer.

13 posted on 01/11/2005 2:23:38 PM PST by Eagle9
[ Post Reply | Private Reply | To 11 | View Replies]

To: UseYourHead
Thanks. I have several friends that could benefit from your answers, especially on large patches.
14 posted on 01/11/2005 2:27:15 PM PST by Eagle9
[ Post Reply | Private Reply | To 12 | View Replies]

To: FreeKeys
Putting your financial information in a windows OS that has active outlook exp. and Internet E. is an exercise in Russian Roulette! Unless the person is quite adept when it comes to computers (in which case the person would probably not be using the above, unless the person works for MSFT).

However there are legions who think the latest patch will help them (even though they have downloaded several patches in a row that are supposed to fix prior patches that were supposed to fix previous patches .....ad nauseum). I'd not be surprised if such people useAOL as well. LOL.

15 posted on 01/11/2005 2:31:35 PM PST by spetznaz (Nuclear tipped ICBMs: The Ultimate Phallic Symbol.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Eagle9

No problem - ask any time, everyone else does!


16 posted on 01/11/2005 2:33:34 PM PST by UseYourHead (Beware of the Rinos - McCain, Hagel, Lugar, and Specter)
[ Post Reply | Private Reply | To 14 | View Replies]

To: FreeKeys
Seems like the discovery of Windows flaws NEVER ends. Will it EVER be safe to put your identity/credit card/bank acct. info on your computer using THIS O/S?

Sure it is, I've done since the late 90's without any problems. I maintain all of our family's accounts and buy literally 100's of things online every year. I've never had a virus and have never had any problems with identity theft.

You just have to put thought into being secure. Run a firewall, put yourself behind a NAT router that does stateful packet inspection, run a virus scan app, run something Like Microsoft AnitSpyware or AdAware, use strong passwords and you should have no problems.
17 posted on 01/11/2005 2:34:11 PM PST by TexasGunLover ("Either you're with us or you're with the terrorists."-- President George W. Bush)
[ Post Reply | Private Reply | To 3 | View Replies]

To: KwasiOwusu

MSFT tries to fix prior attempts to fix prior attempts to fix a fix (or maybe, just maybe,these are new bugs).


18 posted on 01/11/2005 2:35:36 PM PST by spetznaz (Nuclear tipped ICBMs: The Ultimate Phallic Symbol.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 7.62 x 51mm
I still think that Apple/Mac/Linux moles work at MS, building this stuff into the Win O/S, on purpose.

LOL. My personal conspiracy vein runs something like this. I think MSFT plugs in the flaws and bugs on purpose so that they can have people continuously upgrade to 'new' versions. And that they know how to make Windows tighter than a Romanian nun, but decide not to so that when the 'new and amazing' LongHorn OS comes out people 'upgrade' to it.

As i said, this is my conspiratory assessment, but i would not be surprised if it was 100% true. (P.S: I am also pretty sure that B. Gates would never use anything as flaw-ridden as Windows, outlook or IE. And since he would never use a competing OS, mail service or browser one has to assume that what he uses is a version of Windows XP that has been streamlined. As in i think that the commercially available versions have amazingly great engineered obsolescence -plus a plethora of flaws- and Bill Gates uses an in-house version that does not have all the flaws. Again, this is just me mulling on the stuff, but i know there is no way Gates would be using the stuff as it currently is.)

I also think MSFT could make the current windows even better TODAY than the LongHorn OS coming out in a couple of years from now.

19 posted on 01/11/2005 2:42:50 PM PST by spetznaz (Nuclear tipped ICBMs: The Ultimate Phallic Symbol.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Eagle9
How can I down load the windows updates to my CD burner drive instead of my c drive so that I can put it in the desktop and save a ton of time?

Have windows scan for updates
Note the # of the recommended update e.g. KB84342
Go to MS downloads & search for above #, &save to disk.

By the way, where would I find the fixes, updates and patches on my hard-drive?

Windows update page will tell you if you select that option.
Else, they're listed in add/remove programs & C:\wind.. >>uninstall

20 posted on 01/11/2005 2:58:03 PM PST by TheOracleAtLilac
[ Post Reply | Private Reply | To 13 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson