On TechRepublic: Who made the worst PC ever?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos, News.com
Posted on ZDNet News: Aug 18, 2004 7:47:00 PM

Security researchers say they're starting to find flaws in Microsoft's latest major update for Windows XP.

Last week, German company Heise Security announced that two flaws could be used to circumvent the new warnings that Windows XP Service Pack 2, or SP2, normally would display about running untrusted programs, potentially giving a leg up to a would-be intruder's attempts to execute code on a victim's PC.

And more revelations about vulnerabilities are on the way, Thor Larholm, senior security researcher with vulnerability-assessment company PivX Solutions, said Wednesday. Larholm has been looking for holes in the security of SP2 since the update was released and has notified Microsoft about several issues, but he would not discuss the details.

"I'm positive that we will see critical flaws over the next few weeks, and worms that will circumvent SP2 features over the next few months," he said.

Larholm has found dozens of flaws in Windows XP and Internet Explorer over the past few years and had previously maintained a Web page of unpatched vulnerabilities in the software giant's browser.

Microsoft would not discuss whether it had received reports of new vulnerabilities in Windows XP Service Pack 2 but did say that the company's researchers had investigated the Heise issues and found them wanting.

"The security response center is investigating those reports," said a representative of the company. "This feature is one that is supposed to protect users against executable files from an unknown source or untrusted locations. At this time, (Microsoft's security response center is) not aware of any instance that attackers could specifically bypass the service through e-mail or a browser."

Security researchers also point out that Microsoft has not solved some well-known issues with a few of the security technologies incorporated into SP2. Though the firewall is improved, it can be circumvented by any locally running program, a problem with most personal firewall programs, said Marc Maiffret, chief hacking officer for security software maker eEye Digital Security. Maiffret and his staff are analyzing the security update as well.

"We have seen some interesting things, but it is only about a week into it," Maiffret said.

The flaw reports could cause companies to hesitate even more before installing Microsoft's latest step to secure Windows. Many companies have said they will hold off on the update until it has been thoroughly vetted.

SP2 is designed to add better security to the operating system's handling of network data, program memory, browsing activity and e-mail messages by changing the system's code and configuration. For example, a revamped firewall is intended to keep attackers out and attempts to prevent malicious applications from connecting to the Internet by requiring that the user give specific permission to each application.

The major software update, which took almost a year to create, came to life after the MSBlast worm hit the Internet on Aug. 11. Almost 26 days before, Microsoft had issued a patch for the security hole the worm exploited, but many people did not install the fix even though there was widespread expectation that a virus would be created to take advantage of the flaw.

Microsoft Chair Bill Gates has described SP2 as the most extensive free update to Windows ever, and executives have acknowledged that work on the update has delayed other projects, including Longhorn, the next major version of Windows.

In addition to making the software available via automatic update, Microsoft will allow information-technology managers to download an upgrade that companies can use to update their machines.

As for flaws in XP itself, eEye's Maiffret points out that the update is about making Windows XP more secure by adding new protection features and better configuration, not about finding all the vulnerabilities in the operating system.

"Microsoft never claimed that SP2 would close all the security holes," he said.

CNET News.com's Ina Fried contributed to this report.

  • Talkback
  • Most Recent of 112 Talkback(s)
window xp professinal sp2
why do I need this update of service pack for sp2 (Read the rest)
Posted by: mary_the_martion2003@... Posted on: 04/14/05 You are currently: Logged In | Log out
I think we all expected some flaws in it... Monkey_MCSE   | 08/18/04
by public, I mean to Windows Update(NT) Monkey_MCSE   | 08/18/04
Norton AV is NOT RECOGNIZED in Security Center? cglrcng@...   | 08/30/04
Plus ca change Expatriate US Geek   | 08/18/04
... plus c'est la meme chose. Yes. Anton Philidor   | 08/18/04
What a shock NonZealot   | 08/18/04
What are you talking about? TimeBomb   | 08/18/04
Well said but you are wasting your time Squawkbox   | 08/18/04
M$ u$er$ are SO dumb, all I would have to do is send... jguyp725@...   | 08/19/04
Your an Idiot thirstydog@...   | 08/19/04
Not correct balsover   | 08/19/04
These are not a critical problems. heatlesssun   | 08/18/04
Agreed seosamh_z   | 08/18/04
And... TimeBomb   | 08/18/04
pretty whimpy vulns. JoeMama_z   | 08/18/04
What?!? Patrick Jones   | 08/19/04
Thank you... TimeBomb   | 08/18/04
Overreaction as usual Mike Cox   | 08/18/04
LOL.. now equations? One your best, Mike.. Xunil_Sierutuf   | 08/18/04
Simple multiplication, Mike?! Anton Philidor   | 08/18/04
Reporters LOL alterego_z   | 08/18/04
"High" math? Cardinal_Bill   | 08/18/04
Hmmmm... ECLS   | 08/18/04
WOOSH!!! John E Wahd   | 08/19/04
Pretty good shallow_diver   | 08/19/04
Homeland Security TWRX   | 08/19/04
Ding Ding Ding Ding Ding Ding...... Xunil_Sierutuf   | 08/18/04
This was reported on August 13,2004 B.O.F.H.   | 08/18/04
Thank you MS alterego_z   | 08/18/04
My favorite part NonZealot   | 08/18/04
Linux with no holes USA Won   | 08/18/04
Be serious for once! TimeBomb   | 08/18/04
Pay no attention to the man behind the curtain balsover   | 08/19/04
Riiiiiiiiiiiiiiiight stevo32   | 08/18/04
Why even bother Gerald Quaglia   | 08/18/04
why? Arm A. Geddon   | 08/18/04
long time no see arm, i've missed you(NT) Monkey_MCSE   | 08/18/04
thx... Arm A. Geddon   | 08/18/04
We Bother Because We're at War LBattis   | 08/18/04
you drink way too much coffee balsover   | 08/19/04
Consumer circus whisperycat   | 08/18/04
I love the way you think NonZealot   | 08/18/04
Prediction: Year 2525, no secure OS yet... No_Ax_to_Grind   | 08/18/04
That is ... Ardian Daka   | 08/19/04
jeez balsover   | 08/19/04
Unless... doctormoriarty   | 08/19/04
mmmmm..... Cleopatra... be back in 15.. er.. 5 minutes.. Xunil_Sierutuf   | 08/19/04
Yeatr 2525 and beyond (... to 9595) Ardian Daka   | 08/19/04
Good grief, some one old enough to remember! No_Ax_to_Grind   | 08/19/04
Not that old ... Ardian Daka   | 08/19/04
Yikes rapson   | 08/19/04
Don't forget the ignore list folks marksashton   | 08/18/04
Believe it or not ZDNET removes your list computer_man   | 08/18/04
Who cares Gerald Quaglia   | 08/18/04
You're probably right FilledOut   | 08/19/04
SP2 Flaws profftoo   | 08/18/04
Yo, No-Ax, When was the last time zOS was hacked? Bit's_Conscience   | 08/18/04
when was the last time someone cared? JoeMama_z   | 08/18/04
That's not a flaw... drewjoh   | 08/18/04
Why the apology? NonZealot   | 08/18/04
No? balsover   | 08/19/04
You can say that Linux is customizable and all richdave   | 08/18/04
When the software works, it works great balsover   | 08/19/04
Yep, when it works it works and when it doesn't FilledOut   | 08/19/04
copy of RH 9 richdave   | 08/20/04
Um.. Patrick Jones   | 08/19/04
I don't agree voska   | 08/19/04
Most MS and Mac end-users balsover   | 08/19/04
Linux is going to continue to be a geeks toy richdave   | 08/20/04
flying C$ircus pj-xmesh   | 08/18/04
It"s always easy to pick on someone else teardropplumb   | 08/18/04
Can i just ask mlindl   | 08/20/04
I am sick of this! nomorems   | 08/20/04
(i.e. in the biz since before Win95) richdave   | 08/20/04
Why did they wait until it was released? dbaelegance   | 08/18/04
Why wait... techboy_z   | 08/19/04
They dont work for MS balsover   | 08/19/04
SP2 Flaws ccr   | 08/18/04
i shouldn't bother.... JoeMama_z   | 08/18/04
Time to get back to the drawing board nichole_knc   | 08/18/04
Problem I am seeing Linux User 147560   | 08/18/04
microsoft;'s sp2 and patches hilda4jc   | 08/18/04
Read the whole thread, richdave   | 08/18/04
Easy answer mikeybrass   | 08/19/04
re:easy answer richdave   | 08/20/04
Please answer this luvneeyore   | 08/19/04
Trust is Trust and a Flaw is a Flaw that needs to be fixed MS= Arrogance Squawkbox   | 08/18/04
I TRUST a security Patch V Sanders   | 08/24/04
re : Pros point to flaws in Windows security update V Sanders   | 08/18/04
Service Pack for SP2 sjan   | 08/18/04
window xp professinal sp2 mary_the_martion2003@...   | 04/14/05
Glad the pros are looking and giving details back to MS FilledOut   | 08/19/04
Why prop them up? techboy_z   | 08/19/04
Microsoft SP2 "Flaws" stevezd   | 08/19/04
DONT FORGET THE ZDNET IDIOT LIST itanalyst   | 08/19/04
LOL.. oh wait.. I might make the next list..! Xunil_Sierutuf   | 08/19/04
IGNORED marksashton   | 08/19/04
OH NO, I'M BEING IGNORED!! itanalyst   | 08/19/04
Hang in there buddy seosamh_z   | 08/19/04
What to do? msboc   | 08/19/04
What To Do itanalyst   | 08/19/04
Inexperienced vs stupid GEM_z   | 08/19/04
SANS Report on XP SP2 itanalyst   | 08/19/04
Where were these "experts" six months ago Hayvern   | 08/19/04
Looks like ZDNet took the day off. No_Ax_to_Grind   | 08/19/04
EXCELLENT PAPER BY SANS...GO HERE itanalyst   | 08/19/04
anyone have a link for sp2 V Sanders   | 08/19/04
Hmmmm...... tslocum7   | 08/20/04
SP2 rizlin608@...   | 08/20/04
The real "Never ending story" MrTrebuko   | 08/25/04
Another problem with SP2 johnfogelman   | 08/27/04
SP2 for windows xp Ruthdoe   | 09/02/04

What do you think?

advertisement
advertisement
Try It Free

Whitepapers & Webcasts

The Green Enterprise

advertisement
Click Here