Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

August 29th, 2008, 07:58 GMT · By

5-Month-Old Unpatched Vulnerability Stretches from Vista SP1 to XP SP3

SHARE:

Adjust text size:


Security
Enlarge picture
Microsoft is in no hurry to patch a vulnerability which it managed to confirm approximately five months ago in mid-April 2008. On August 27, 2008, the Redmond company provided additional details about the security flaw that impacts a wide range of Windows operating systems, including Windows XP Service Pack 3 and SP2, Windows Vista RTM and SP1, Windows Server 2008 and Windows Server 2003. According to the Redmond company, outside of the x64 version of XP, both the 32-bit and 64-bit variants of all supported Windows client and server platforms are affected. The vulnerability, residing within Windows, can potentially allow an attacker to gain elevation of privileges from authenticated users to LocalSystem, in the context of a successful exploit.

 

But part of the reason why Microsoft is not rushing to deliver a patch is the fact that it hasn't detected any exploits designed to take advantage of this specific issue. "Microsoft is not aware of any attacks attempting to exploit the potential vulnerability. Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs," the company noted.

 

In addition to the lack of attacks in the wild, the security issue is not putting end users to a sufficiently high degree of risk to catalyze a more urgent patch either. The general rule at Microsoft is that the level of danger is strictly correlated with the urgency of a security bulletin. Most exposed to this vulnerability are customers using Internet Information Services (IIS) and SQL Server (such as hosting providers) which permit third-party code to be executed and run in an authenticated context.

 

"Specially crafted code running in the context of the NetworkService or LocalService accounts may gain access to resources in processes that are also running as NetworkService or LocalService. Some of these processes may have the ability to elevate their privileges to LocalSystem, allowing any NetworkService or LocalService processes to elevate their privileges to LocalSystem as well," Microsoft added.

 

A patch is not available from the Redmond company but workarounds are provided in order to mitigate the risks associated with the security flaw.


TELL US WHAT YOU THINK:

1,524 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XP SP3 and Vista SP1 August 2008 Security Releases ISO Image

IE8 Beta 1 Updated for XP SP3 and Vista SP1

Microsoft Points the Finger at the Apple OS X Insecure Update Mechanism

XP SP3 and Vista SP1: DirectX 9 and DirectX 10 Patches Updated

Vista SP1 and XP SP3 July 2008 Security Releases ISO Image

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM