NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


2 Year Old Critical Vulnerability Comes Back to Haunt XP SP3 RTM

A patch is available

By Marius Oiaga, Technology News Editor

14th of May 2008, 10:25 GMT

Adjust text size:


Windows
Enlarge picture
The latest service pack for Windows XP, despite being just a standard release, is designed to also take the operating system to a new level of security. The minor evolution represented by the jump from SP2 to SP3 will not bulletproof Windows XP, but what it will do is provide all of the security patches released since late 2004 through Windows Update bundled with the service pack. And yet Windows XP Service Pack 3 RTM Build 5512 is still vulnerable to exploits targeting a security flaw approximately two years old, according to Microsoft.

"We re-released MS06-069 to add XP SP3 as an affected version", revealed Tami Gallupe, MSRC Release Manager. However, this time around, the Redmond company is not at fault. The label of Microsoft Security Bulletin MS06-069 reveals that this issue was patched as far back as 2006, on November 14 in fact. A couple of years ago Microsoft served a security update for vulnerabilities in Flash Player from Adobe that could allow an attacker to perform remote code execution on an operating system affected by the vulnerability, in the eventuality of a successful exploit.

The list of impacted platforms contains not only XP SP2 and SP3 but also Windows Vista (but not Vista SP1). "Vulnerable versions of Macromedia Flash Player from Adobe are redistributed with Microsoft Windows XP Service Pack 2, Microsoft Windows XP Service Pack 3, and Microsoft Windows XP Professional x64 Edition", Microsoft informed after it has updated the security bulletin.

Because the security vulnerability patched by MS06-069 targets a flaw in third party software, the Redmond company has not included the item among the updates in XP SP3 RTM. In this context, end users who perform clean installs of XP SP3 via slipstream integrated versions of the service pack are at risk from exploits unless they apply the patch that is already available. There are not changes in the binaries of the update for XP SP2 in comparison to those for XP SP3.

"Several remote code execution vulnerabilities exist in Macromedia Flash Player from Adobe because of the way that it handles Flash Animation (SWF) files. An attacker could exploit these vulnerabilities by constructing a specially crafted Flash Animation (SWF) file that could potentially allow remote code execution if a user visited a Web site containing the specially crafted SWF file. The specially crafted SWF file could also be sent as an e-mail attachment. A user would only be at risk if opening this e-mail attachment. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system", reads the description of the vulnerability as provided by Microsoft.

TAGS:

Windows XP SP3 RTM | Build 5512 | vulnerability | Falsh
Read by 1,690 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.1/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Enable Vista-Native Network Access Protection on XP SP3

XP SP3 Download Still Live Despite Widespread Problems

9 Critical Errors that Will Prevent the Installation of XP SP3 RTM Build 5512

It All Comes Down to Going Either for XP SP3 or for Vista SP1

Download Windows XP SP3 RTM Network Installation Package

Microsoft Makes Its Own Vista SP1 vs. XP SP2, Leaves XP SP3 Out

Critical Security Patch for Windows XP Service Pack 3 Final

Download Windows XP Service Pack 3 - ISO-9660 CD Image File

New Version of Internet Explorer 7 Available for Windows XP SP3 RTM

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM