NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


5-Month-Old Unpatched Vulnerability Stretches from Vista SP1 to XP SP3

Microsoft is monitoring the situation

By Marius Oiaga, Technology News Editor

29th of August 2008, 07:58 GMT

Adjust text size:


Security
Enlarge picture
Microsoft is in no hurry to patch a vulnerability which it managed to confirm approximately five months ago in mid-April 2008. On August 27, 2008, the Redmond company provided additional details about the security flaw that impacts a wide range of Windows operating systems, including Windows XP Service Pack 3 and SP2, Windows Vista RTM and SP1, Windows Server 2008 and Windows Server 2003. According to the Redmond company, outside of the x64 version of XP, both the 32-bit and 64-bit variants of all supported Windows client and server platforms are affected. The vulnerability, residing within Windows, can potentially allow an attacker to gain elevation of privileges from authenticated users to LocalSystem, in the context of a successful exploit.

 

But part of the reason why Microsoft is not rushing to deliver a patch is the fact that it hasn't detected any exploits designed to take advantage of this specific issue. "Microsoft is not aware of any attacks attempting to exploit the potential vulnerability. Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs," the company noted.

 

In addition to the lack of attacks in the wild, the security issue is not putting end users to a sufficiently high degree of risk to catalyze a more urgent patch either. The general rule at Microsoft is that the level of danger is strictly correlated with the urgency of a security bulletin. Most exposed to this vulnerability are customers using Internet Information Services (IIS) and SQL Server (such as hosting providers) which permit third-party code to be executed and run in an authenticated context.

 

"Specially crafted code running in the context of the NetworkService or LocalService accounts may gain access to resources in processes that are also running as NetworkService or LocalService. Some of these processes may have the ability to elevate their privileges to LocalSystem, allowing any NetworkService or LocalService processes to elevate their privileges to LocalSystem as well," Microsoft added.

 

A patch is not available from the Redmond company but workarounds are provided in order to mitigate the risks associated with the security flaw.

TAGS:

Windows XP SP3 | Windows Vista SP1 | vulnerability | IIS | SQL Server
Read by 1,088 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


XP SP3 and Vista SP1 August 2008 Security Releases ISO Image

IE8 Beta 1 Updated for XP SP3 and Vista SP1

Microsoft Points the Finger at the Apple OS X Insecure Update Mechanism

XP SP3 and Vista SP1: DirectX 9 and DirectX 10 Patches Updated

Vista SP1 and XP SP3 July 2008 Security Releases ISO Image

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM