On GameSpot: Wii Fit tells 10-year-old she's fat
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Aug 18, 2004 7:47:00 PM

Security researchers say they're starting to find flaws in Microsoft's latest major update for Windows XP.

Last week, German company Heise Security announced that two flaws could be used to circumvent the new warnings that Windows XP Service Pack 2, or SP2, normally would display about running untrusted programs, potentially giving a leg up to a would-be intruder's attempts to execute code on a victim's PC.

And more revelations about vulnerabilities are on the way, Thor Larholm, senior security researcher with vulnerability-assessment company PivX Solutions, said Wednesday. Larholm has been looking for holes in the security of SP2 since the update was released and has notified Microsoft about several issues, but he would not discuss the details.

"I'm positive that we will see critical flaws over the next few weeks, and worms that will circumvent SP2 features over the next few months," he said.

Larholm has found dozens of flaws in Windows XP and Internet Explorer over the past few years and had previously maintained a Web page of unpatched vulnerabilities in the software giant's browser.

Microsoft would not discuss whether it had received reports of new vulnerabilities in Windows XP Service Pack 2 but did say that the company's researchers had investigated the Heise issues and found them wanting.

"The security response center is investigating those reports," said a representative of the company. "This feature is one that is supposed to protect users against executable files from an unknown source or untrusted locations. At this time, (Microsoft's security response center is) not aware of any instance that attackers could specifically bypass the service through e-mail or a browser."

Security researchers also point out that Microsoft has not solved some well-known issues with a few of the security technologies incorporated into SP2. Though the firewall is improved, it can be circumvented by any locally running program, a problem with most personal firewall programs, said Marc Maiffret, chief hacking officer for security software maker eEye Digital Security. Maiffret and his staff are analyzing the security update as well.

"We have seen some interesting things, but it is only about a week into it," Maiffret said.

The flaw reports could cause companies to hesitate even more before installing Microsoft's latest step to secure Windows. Many companies have said they will hold off on the update until it has been thoroughly vetted.

SP2 is designed to add better security to the operating system's handling of network data, program memory, browsing activity and e-mail messages by changing the system's code and configuration. For example, a revamped firewall is intended to keep attackers out and attempts to prevent malicious applications from connecting to the Internet by requiring that the user give specific permission to each application.

The major software update, which took almost a year to create, came to life after the MSBlast worm hit the Internet on Aug. 11. Almost 26 days before, Microsoft had issued a patch for the security hole the worm exploited, but many people did not install the fix even though there was widespread expectation that a virus would be created to take advantage of the flaw.

Microsoft Chair Bill Gates has described SP2 as the most extensive free update to Windows ever, and executives have acknowledged that work on the update has delayed other projects, including Longhorn, the next major version of Windows.

In addition to making the software available via automatic update, Microsoft will allow information-technology managers to download an upgrade that companies can use to update their machines.

As for flaws in XP itself, eEye's Maiffret points out that the update is about making Windows XP more secure by adding new protection features and better configuration, not about finding all the vulnerabilities in the operating system.

"Microsoft never claimed that SP2 would close all the security holes," he said.

CNET News.com's Ina Fried contributed to this report.

  • Talkback
  • Most Recent of 112 Talkback(s)
window xp professinal sp2
why do I need this update of service pack for sp2 (Read the rest)
Posted by: mary_the_martion2003@yahoo.ca Posted on: 04/14/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
I think we all expected some flaws in it...  Monkey_MCSE | 08/18/04
by public, I mean to Windows Update(NT)  Monkey_MCSE | 08/18/04
Norton AV is NOT RECOGNIZED in Security Center?  cglrcng@... | 08/30/04
Plus ca change  Expatriate US Geek | 08/18/04
... plus c'est la meme chose. Yes.  Anton Philidor | 08/18/04
What a shock  NonZealot | 08/18/04
What are you talking about?  TimeBomb | 08/18/04
Well said but you are wasting your time  Squawkbox | 08/18/04
M$ u$er$ are SO dumb, all I would have to do is send...  jguyp725@... | 08/19/04
Your an Idiot  thirstydog@... | 08/19/04
Not correct  balsover | 08/19/04
These are not a critical problems.  heatlesssun | 08/18/04
Agreed  seosamh_z | 08/18/04
And...  TimeBomb | 08/18/04
pretty whimpy vulns.  JoeMama_z | 08/18/04
What?!?  Patrick Jones | 08/19/04
Thank you...  TimeBomb | 08/18/04
Overreaction as usual  Mike Cox | 08/18/04
LOL.. now equations? One your best, Mike..  Xunil_Sierutuf | 08/18/04
Simple multiplication, Mike?!  Anton Philidor | 08/18/04
Reporters LOL  alterego_z | 08/18/04
"High" math?  Cardinal_Bill | 08/18/04
Hmmmm...  ECLS | 08/18/04
WOOSH!!!  John E Wahd | 08/19/04
Pretty good  shallow_diver | 08/19/04
Homeland Security  TWRX | 08/19/04
Ding Ding Ding Ding Ding Ding......  Xunil_Sierutuf | 08/18/04
This was reported on August 13,2004  B.O.F.H. | 08/18/04
Thank you MS  alterego_z | 08/18/04
My favorite part  NonZealot | 08/18/04
Linux with no holes  USA Won | 08/18/04
Be serious for once!  TimeBomb | 08/18/04
Pay no attention to the man behind the curtain  balsover | 08/19/04
Riiiiiiiiiiiiiiiight  stevo32 | 08/18/04
Why even bother  DarthRidiculous | 08/18/04
why?  Arm A. Geddon | 08/18/04
long time no see arm, i've missed you(NT)  Monkey_MCSE | 08/18/04
thx...  Arm A. Geddon | 08/18/04
We Bother Because We're at War  LBattis | 08/18/04
you drink way too much coffee  balsover | 08/19/04
Consumer circus  whisperycat | 08/18/04
I love the way you think  NonZealot | 08/18/04
Prediction: Year 2525, no secure OS yet...  No_Ax_to_Grind | 08/18/04
That is ...  Ardian Daka | 08/19/04
jeez  balsover | 08/19/04
Unless...  doctormoriarty | 08/19/04
mmmmm..... Cleopatra... be back in 15.. er.. 5 minutes..  Xunil_Sierutuf | 08/19/04
Yeatr 2525 and beyond (... to 9595)  Ardian Daka | 08/19/04
Good grief, some one old enough to remember!  No_Ax_to_Grind | 08/19/04
Not that old ...  Ardian Daka | 08/19/04
Yikes  rapson | 08/19/04
Don't forget the ignore list folks  marksashton | 08/18/04
Believe it or not ZDNET removes your list  computer_man | 08/18/04
Who cares  DarthRidiculous | 08/18/04
You're probably right  FilledOut | 08/19/04
SP2 Flaws  profftoo | 08/18/04
Yo, No-Ax, When was the last time zOS was hacked?  Bit's_Conscience | 08/18/04
when was the last time someone cared?  JoeMama_z | 08/18/04
That's not a flaw...  drewjoh | 08/18/04
Why the apology?  NonZealot | 08/18/04
No?  balsover | 08/19/04
You can say that Linux is customizable and all  richdave | 08/18/04
When the software works, it works great  balsover | 08/19/04
Yep, when it works it works and when it doesn't  FilledOut | 08/19/04
copy of RH 9  richdave | 08/20/04
Um..  Patrick Jones | 08/19/04
I don't agree  voska | 08/19/04
Most MS and Mac end-users  balsover | 08/19/04
Linux is going to continue to be a geeks toy  richdave | 08/20/04
flying C$ircus  pj-xmesh | 08/18/04
It"s always easy to pick on someone else  teardropplumb | 08/18/04
Can i just ask  mlindl | 08/20/04
I am sick of this!  nomorems | 08/20/04
(i.e. in the biz since before Win95)  richdave | 08/20/04
Why did they wait until it was released?  dbaelegance | 08/18/04
Why wait...  techboy_z | 08/19/04
They dont work for MS  balsover | 08/19/04
SP2 Flaws  ccr | 08/18/04
i shouldn't bother....  JoeMama_z | 08/18/04
Time to get back to the drawing board  nichole_knc | 08/18/04
Problem I am seeing  Linux User 147560 | 08/18/04
microsoft;'s sp2 and patches  hilda4jc | 08/18/04
Read the whole thread,  richdave | 08/18/04
Easy answer  mikeybrass | 08/19/04
re:easy answer  richdave | 08/20/04
Please answer this  luvneeyore | 08/19/04
Trust is Trust and a Flaw is a Flaw that needs to be fixed MS= Arrogance  Squawkbox | 08/18/04
I TRUST a security Patch  V Sanders | 08/24/04
re : Pros point to flaws in Windows security update  V Sanders | 08/18/04
Service Pack for SP2  sjan | 08/18/04
window xp professinal sp2  mary_the_martion2003@... | 04/14/05
Glad the pros are looking and giving details back to MS  FilledOut | 08/19/04
Why prop them up?  techboy_z | 08/19/04
Microsoft SP2 "Flaws"  stevezd | 08/19/04
DONT FORGET THE ZDNET IDIOT LIST  itanalyst | 08/19/04
LOL.. oh wait.. I might make the next list..!  Xunil_Sierutuf | 08/19/04
IGNORED  marksashton | 08/19/04
OH NO, I'M BEING IGNORED!!  itanalyst | 08/19/04
Hang in there buddy  seosamh_z | 08/19/04
What to do?  msboc | 08/19/04
What To Do  itanalyst | 08/19/04
Inexperienced vs stupid  GEM_z | 08/19/04
SANS Report on XP SP2  itanalyst | 08/19/04
Where were these "experts" six months ago  Hayvern | 08/19/04
Looks like ZDNet took the day off.  No_Ax_to_Grind | 08/19/04
EXCELLENT PAPER BY SANS...GO HERE  itanalyst | 08/19/04
anyone have a link for sp2  V Sanders | 08/19/04
Hmmmm......  tslocum7 | 08/20/04
SP2  rizlin608@... | 08/20/04
The real "Never ending story"  MrTrebuko | 08/25/04
Another problem with SP2  johnfogelman | 08/27/04
SP2 for windows xp  Ruthdoe | 09/02/04

What do you think?

advertisement
Click Here