Serious security vulnerabilities
Serious security vulnerabilities
R E L A T E D   C O N T E N T
ADVERTISEMENT

Ten SP2 flaws leave XP users open to hackers

Millions at risk from 'silent and remote' attacks, claims security firm

Robert Jaques, vnunet.com 11 Nov 2004
ADVERTISEMENT

Security researchers claimed today that millions of Microsoft customers are at risk from 10 serious security vulnerabilities uncovered in Windows XP patched with Service Pack 2 (SP2).

By exploiting all the vulnerabilities discovered in SP2 by security firm Finjan, attackers could "silently and remotely" take over an SP2 machine when the user simply browses a web page.

Finjan claimed that hackers could also switch between Internet Explorer security zones to obtain rights of local zone Internet Explorer users.

This could make it possible to elevate the privilege level of mobile code downloaded from the internet, thereby allowing the remote code to read, write and execute files on the user's hard drive.

According to Finjan, hackers could also bypass XP SP2's notification mechanism on the download and execution of .exe files, and therefore download files without any warning or notification.

Finjan's Malicious Code Research Center, which claims to have identified the flaws, has provided Microsoft with full technical details and has been assisting the software giant to patch the holes.

Although it warned users about the alleged flaws, the security firm refused to provide specific details.

"In order to prevent the creation of malicious viruses and worms, Finjan will not release any technical details about these vulnerabilities until they are fully patched by Microsoft," it stated.

Shlomo Touboul, chief executive and founder of Finjan Software, added: "The recently released XP SP2 operating system offers certain security features.

"However, it suffers because it is still basically the same operating system and has some major flaws which compromise end-user security."

See also:

Academic study suggests Microsoft produces more secure codeVulnerability research claims shocking results  17 Feb 2005
MS04-039 patch updatedBetter safe than sorry  17 Nov 2004
Applications under threatHas someone sold you a lemon?  17 Nov 2004
Patch causing ongoing problemsUsers installing security update by themselves wreak havoc  16 Nov 2004
Smaller firms falling behindFinancial Services Authority warns SMEs to tighten security  15 Nov 2004
Trustworthy ComputingTrustworthy Computing programme lives on  04 Nov 2004
Service Pack 2 migration fearsStudy claims half of IT managers expect migration 'issues'  03 Nov 2004
Ten security patches'Critical' vulnerabilities could allow attackers to gain complete control  13 Oct 2004
Microsoft chief executive Steve BallmerSafe surfing means switching to XP, says Steve Ballmer  05 Oct 2004
Windows XP SP2What IT managers need to know about XP SP2  15 Sep 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities