Security Firm Reports Ten New XP SP2 Flaws

Moderators: Moderator, Global Moderator

Post Reply
RuffRyders
Newbie
Newbie
Posts: 0
Joined: Mon Jun 14, 2004 7:47 am

Security Firm Reports Ten New XP SP2 Flaws

Post by RuffRyders »

Security Firm Reports Ten New XP SP2 Flaws
A security company says it has discovered a series of security flaws in Microsoft Windows XP Service Pack 2 that would allow a hacker to take over an SP2 machine when the user browses a Web page. Microsoft downplayed the claims by Finjan Software.

A security firm says it has found 10 major security flaws in Microsoft's Windows XP Service Pack 2. The weaknesses could allow intruders to bypass many of the security measures implemented by the update.

A hacker could exploit the flaws to execute malicious code on a user's system by luring the user to a specially created Web page, according to Finjan Software, which reported the vulnerability.

Finjan has passed the exploit's full technical details to Microsoft but said it will not make them public until the Redmond, Washington-based software firm has developed patches.

Bypassing Alerting System
Finjan, which sells security software that it says will plug the holes, claimed that the vulnerabilities enable a Web page to access a local file, elevating the privileges of code downloaded from the Internet and bypassing Windows XP SP2's system for warning users about the download and execution of program files.

"By exploiting all vulnerabilities discovered in SP2 by Finjan, attackers can silently and remotely take over an SP2 machine when the user simply browses a Web page," Finjan says in a statement.

Conflict of Interest
The fact that Finjan is not publishing any details about the alleged vulnerabilities in Windows XP SP2 makes it difficult for other security companies to ascertain the truth of its claims.

Given that Finjan sells software that is designed to patch vulnerabilities like those it says it has identified in XP SP2, there would appear to be something of a conflict of interest.

Microsoft was quoted in press reports as saying that it disputed Finjan's claims and that they were "potentially misleading and possibly erroneous regarding the breadth and severity of the alleged vulnerabilities in Windows XP SP2."

Fix Required
"We provided Microsoft with all the technical details, including the software code that can create the vulnerabilities," Gil Arditi, chief security officer at Finjan Software, told NewsFactor. "We think that Microsoft will solve the problem and publish a fix."

Finjan sees the vulnerabilities as potentially very serious. "Basically, you can do anything you want if you take control of someone's PC remotely," Shlomo Touboul, chief executive officer and founder of Finjan Software, told NewsFactor. "If you plant code on someone' computer, you can destroy the machine, you can send out Trojans. In recent months, we have seen worms that turn computers into Web servers that launch attacks on other computers."

[Source]
The bruises fade but memories are made.
Post Reply

Return to “Security”