Zero Day Windows XP SP2 Security HoleBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Windows Security : Zero Day Windows XP SP2 Security Hole
Posted by Max on 2007/9/20 13:48:30 (743 reads)
Windows Security

Security researchers are reporting a new security hole in Windows XP Service Pack 2 – the only "supported" version of XP – that could lead to complete compromise of your PC.

There have been no attacks so far, but proof-of-concept code is available online, so it's good to be aware that a potential problem is out there.

The hole was found by Jonathan Sarba of the GoodFellas Security Research Team, who said on the team's Website that Microsoft had been first notified of the defect in late June, and was contacted regarding it repeatedly after that.

Research firm Secunia rates the risk at "moderately critical" the third tier of its five-tier severity rating scale. The problem lies in a pair of files that are part of XP's system code, but just because it's dweeby doesn't mean it isn't dangerous.

According to Secunia's alert HP All-in-One Series Web Release software/driver installer version 2.1.0 and HP Photo &Imaging Gallery version 1.1 are both vulnerable.

What's called the "attack vector" is yet another classic buffer overflow exploit. (Don't get me started.)

Meanwhile, Christopher Budd, security program manager at Microsoft said in a statement that the company "is investigating new public claims of a possible vulnerability in Microsoft Windows."

The statement is standard boiler plate, and says that if a problem is identified, Microsoft will figure out whether to issue an "out-of-cycle" update or to patch the bug as part of the Patch Tuesday process (so-called because Microsoft releases new patches on the second Tuesday of every month).

While we wait for Microsoft's verdict, keep your eyes and ears open for reports of real world attacks, especially if you run either of those pieces of HP software, because there is no fix or workaround just yet.




Other articles
2008/8/21 15:52:01 - BitRoll and Torrent101 Used to Distribute the Lop Adware
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft

The comments are owned by the poster. We aren't responsible for their content.