ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Microsoft warns again on Windows

David Becker CNET News.com

Published: 24 Jul 2003 07:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft issued another slew of warnings about security holes on Wednesday, including a "critical" flaw that affects most Windows PCs.

The most serious of the flaws involves DirectX, a library of graphics and multimedia programming instructions used by most PC games, and could allow malicious users to run code of their choice on a vulnerable PC.

The flaw is unusually widespread, affecting all versions of DirectX from version 5.2 to the current 9.0a running on all versions of Windows from Windows 98 through the new Windows Server 2003, according to the Microsoft bulletin.

The flaw, which received Microsoft's highest severity rating, involves the way DirectX handles MIDI music files. A malformed MIDI file could overrun the buffer in DirectX, at which point extra software embedded in the file would be executed.

Exploiting the flaw would entail the creation of a maliciously malformed MIDI file, which vulnerable Windows users would have to be tricked into running, either through email or a Web page. "They'd have to come up with some way to get the user to click on that file," Stephen Toulouse of Microsoft's Security Response Centre said, noting that default security settings in recent versions of Microsoft Outlook email software and the Internet Explorer Web browser prevent the automatic launching of such files.

Default security settings are even stronger in Windows Server 2003, Toulouse added, which is why the flaw has a lower rating of "important" for that operating system.

Toulouse said there are no known exploits of the flaw, which was discovered by eEye Digital Security, but that affected Windows users should still apply the appropriate patch as soon as possible.

Microsoft also announced the availability of a cumulative patch -- rated "important" -- that fixes new and previously reported vulnerabilities in the company's SQL Server software.

A third bulletin warned of a "moderate" risk for a new method to launch a denial-of-service attack against a PC that runs the Windows NT 4.0 operating system.

The latest alerts continue a busy month of security issues for the software giant.

Mike Cherry, an analyst for research firm Directions on Microsoft, said the frequency of security alerts could be bad for Microsoft's image, particularly as they relate to Windows Server 2003, one of the first poster children for the company's "trustworthy computing" initiative.

"There should be some concern that, even with the improved testing in that product, they're continuing to find these problems," he said.

But no software maker can find every flaw before a product is released, Cherry said, and at least Microsoft is being upfront about potential problems.

"They're getting much better about discussing these problems as they're found," he said. "We never would have gotten this kind of information three years ago."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
49 out of 100 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Senior SQL Server DBA Opportunity for Major Financials

Are you a SQL Server DBA? Do you have exposure to sql server 2005? Do you wish to work with the latest technologies ? A SQL Server DBAis needed for a ...

IT Developer - .Net ( SQL Server, C#, VB.Net, .Net) - Guildford

IT DEVELOPER - .NET ( SQL SERVER, C#, VB.NET, .NET) Guildford, Surrey 28,000 35,000 dependent on experience Our client is an international HR ...

Data Warehouse Consultant, SQL Server

A Data Warehouse Consultant with strong SQL Server and ETL experience is needed for a market leading software supplier in Manchester. Any experience ...

Discussions

Moley Moley

It might be nice

Saturday 5 July 2008, 8:24 PM

1 comment
348156 348156

Quite Ridiculous

Saturday 5 July 2008, 12:47 PM

5 comments
spookie spookie

Laptop wont boot up

Saturday 5 July 2008, 12:51 AM

2 posts

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal