NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Not a Single Scratch on Vista, as Microsoft Patches XP and Windows Server 2003

Just two security patches in November

By Marius Oiaga, Technology News Editor

14th of November 2007, 08:09 GMT

Adjust text size:


Windows Update
Enlarge picture
As Microsoft is hard at work patching Windows XP and Windows Server 2003, Windows Vista managed to get by without a single scratch. On November 13, the Redmond company made available two security bulletins addressing vulnerabilities in XP and Windows Server 2003. The updates are designed to patch two security holes rated as Critical and Important, respectively, by Microsoft, with the maximum severity flaw having been actively
exploited in the wild, via publicly available proof-of-concept code.

Microsoft Security Bulletin MS07-061, rated as Critical, deals with a vulnerability in Windows URI Handling that in the eventuality of a successful attack allows for remote code execution. This issue was reported to the company in October, and it is generated by the way Windows manages malformed URLs. "A remote code execution vulnerability exists in the way that the Windows shell handles specially crafted URIs that are passed to it. If the Windows shell did not sufficiently validate these URIs, an attacker could exploit this vulnerability and execute arbitrary code. Microsoft has only identified ways to exploit this vulnerability on systems using Internet Explorer 7. However, the vulnerability exists in a Windows file, Shell32.dll, which is included in all supported editions of Windows XP and Windows Server 2003", Microsoft revealed.

The Redmond company has also patched a security hole in the Microsoft DNS Server service on Windows 2000 Server SP4, Windows Server 2003 SP1 & SP2, Windows Server 2003 x64, Windows Server 2003 x64 SP2, Windows Server 2003 Itanium SP1 & SP2, via Security Bulletin MS07-062. "This spoofing vulnerability exists in Windows DNS Servers and could allow an attacker to send specially crafted responses to DNS requests, thereby spoofing or redirecting Internet traffic from legitimate locations", Microsoft added.

While none of the security bulletins issued this month target Windows Vista, this does not mean that Microsoft's latest operating system will go without updating. In fact, there are no less than three non-security updates released designed to soften some of the rough edges of the operating system, a mere preview of Windows Vista SP1.

TAGS:

Windows XP | Windows Server 2003 | Windows Vista | vulnerability | patch
Read by 978 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.5/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 7 Is an Open Door for Attacks

What Is the Fastest Way to Windows' Heart?

Vista Safe from Fresh XP Zero-Day

Windows XP SP3 Beta Coming Up?

Vista Still Breathing as XP Chokes on Latest Vulnerability

Happy Birthday Internet Explorer 7! Microsoft: Install IE7 Even on Pirated Windows(!)

Evaluate System Center Configuration Manager 2007

Microsoft to Strip Windows Server 2008 RC1

Forget about XP SP3, and Vista SP1, Have a Taste of Windows 7

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM