HOME  |  PROFILE  |  CONTACT US Friday  10 September, 2010
 

Security /  LANs & WANs /  Network Management /  Wireless /  Virtualisation /  Data Centre /  Cabling /  Servers and Storage /  Collaboration /  Case Studies /  Unified Communications
Microsoft 'working' on patch for critical Windows vulnerability

Microsoft is working on a patch to prevent exploits of a newly discovered vulnerability that affects all versions of Windows.

LANs & WANs
by Staff  Wednesday, July 21 2010

E-mail
Comments
Print 367 views

Microsoft acknowledged the flaw in a security advisory Friday, while offering a workaround, but not a patch. Microsoft updated the advisory on Monday with a short statement that "Microsoft is currently working to develop a security update for Windows to address this vulnerability."

Microsoft kills security updates, support for Windows 2000, XP Service Pack 2

Microsoft recently allowed one vulnerability affecting an older version of Office to go unpatched, but since the latest exploit affects all versions of Windows it would be highly unlikely for Microsoft to not issue a permanent fix.

Microsoft did not say whether it will wait until the next regularly scheduled Patch Tuesday, Aug. 10, to issue the patch or whether it will do so earlier than that. Time may be of the essence, as attacks have already been reported and a working exploit was published by a security researcher, perhaps ensuring that more attacks will occur.

Related content

Virtual possibilities

Microsoft to add privacy features to IE8

Microsoft pitches proactive enterprise support
Other articles under this section
The new vulnerability affects Windows Shell, the Windows graphical user interface, and allows attackers to hack systems using malicious shortcut files. The vulnerability could be exploited remotely, but is more likely to be exploited using removable drives, such as USB sticks, according to Microsoft. The vulnerability exists because Windows incorrectly parses shortcuts, allowing the execution of malicious code.

"An attacker could present a removable drive to the user with a malicious shortcut file, and an associated malicious binary," Microsoft says. "When the user opens this drive in Windows Explorer, or any other application that parses the icon of the shortcut, the malicious binary will execute code of the attacker's choice on the victim system. An attacker could also set up a remote network share, and place the malicious components on this share. When the user browses the share, Windows will attempt to load the icon of the shortcut file, and the malicious binary may be invoked."

Microsoft offered two workarounds, including one that disables icons from being displayed for shortcuts, and another that disables the WebClient service, blocking a possible remote attack vector.

These workarounds were described as "highly impractical for most environments" by Chester Wisniewski, a security researcher at Sophos.

Tags

Microsoft (823)
E-mail
Print


Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics









Quick Poll

How many terabytes of storage does each storage admin at your company manage?






» View result
Comment



Screen Name 
E-mail 
Subject
Comment  
Enter code:
  

Most read


View more news



Most commented
Currently no comments have been submitted for this section.
View more news




Whitepaper

The Impact of the Carbon Reduction in Data Centres

Due to their high electrical power consumption, data centres in the majority of cases will be affected and it will prove difficult over time to reduce emissions and at the same time sustain expansion and growth. This paper is intended to provide a brief overview of the CRC, how it will affect businesses and how improvements to energy efficiency can be made with changes to the ICT infrastructure.
Next Generation Data Centre ICT Infrastructures

In addition to server consolidation and virtualisation, recent trends towards Service Orientated Architectures (SOAs), Web 2.0 applications and cluster computing are accelerating the implementation of unified network fabrics in order to cope with the higher I/O throughput and greater bandwidth needed to deliver these services.
Energy Savings with 10GBase-T and Energy Efficient Ethernet

Energy Efficient Ethernet is an emerging IEEE802.3az standard due to be ratified in 2010 and focuses on power savings when an Ethernet device is sitting idle.


View all whitepapers


Video Archive 

Copyright 2010 IDG Middle East. All rights reserved. Reproduction in whole or in part in any form or medium without express written permission of IDG Middle East is prohibited.