NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Windows

Windows


Microsoft Details Windows XP SP3 Secret Changes

And says it's not about security

By Marius Oiaga, Technology News Editor

9th of January 2008, 09:19 GMT

Adjust text size:


Windows XP
Enlarge picture
If you think that all the changes that Microsoft is introducing with Windows XP Service Pack 3 are included into the official overview of the refresh, then you are sadly mistaking. The fact of the matter is that there is simply more than meets the eye, with the third and final service pack for XP, and changes run deep under the hood of the operating system. And while the Redmond company has illustrated the evolution to SP3 by referencing the addition of such functionality, as the MMC 3.0 framework, MSXML6, Windows Installer 3.1 v2, Background Intelligent Transfer Service 2.5, IPsec Simple Policy Update for Windows Server 2003 and Windows XP, Digital Identity Management Service, Peer Name Resolution Protocol, Wi-Fi Protected Access 2, "Black Hole" Router Detection, Network Access Protection and Kernel Mode Cryptographic Module, it has also managed to leave out additional details concerning other areas of the platform.

"Windows XP Service Pack 3 (SP3) includes all previously released Windows XP updates, including security updates and hotfixes. It also includes select out-of-band releases,
and a small number of new enhancements, which do not significantly change customers' experience with the operating system.(...) Microsoft is not adding significant functionality from newer versions of Windows, such as Windows Vista, to Windows XP through XP SP3. [However] SP3 does include Network Access Protection (NAP) to help organizations that use Windows XP to take advantage of new features in the Windows Server 2008 operating system", Microsoft revealed in the service pack's overview.

IDA disassembly
Enlarge picture
But, XP SP3 also brings to the table modifications impacting the DCE/RPC - Distributed Computing Environment/Remote Procedure Call. A detailed comparison of the modifications between DCERPC services on XP SP2 and XP SP3 (release candidate) has been published on Full Disclosure. And while the document is mostly unintelligible outside of professionals, Microsoft managed to detail the XP SP3 range check, denying that it was hiding an overflow condition.

"We have received a few inquiries about the full disclosure posting [over Windows XP SP3 - DCERPC Changes], where a range check was added in Windows XP SP3 for the Terminal Server RPC function RpcWinStationEnumerateProcesses. The speculation stated that this change was to hide an overflow condition, potentially leading to an exploitable vulnerability in previous Windows versions. In reality, this update to the Terminal Service RPC interface definition was made to better adhere to our own RPC best practices", explained a member of the Security Vulnerability Research & Defense team, subsequently citing the resource for IDL techniques interface and method design.

TAGS:

Windows XP | SP3 | DCERPC
Read by 7,623 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.3/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Deploying Windows XP SP3

Microsoft Wakes Up at the Sound of Windows XP SP3 RC

The Evolution of the Windows XP SP3 Activation Architecture

Microsoft Downplays Windows XP SP3 and Points to Windows Vista

Download Windows XP Service Pack 3 Build 3264- Right Here!

Download the Official Windows XP SP3 Overview

Microsoft: Windows XP SP3 Available EARLY(!) in 2008

Windows XP SP3 RTM and Windows Vista SP1 RTM - Just Around the Corner?

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM