All the latest UK technology news, reviews and analysis

Windows open to critical vulnerabilities

by Robert Jaques

12 Jan 2005

Be the first to comment

  • Tweet this

Microsoft has detailed three newly discovered security flaws, two of which it rates as 'critical' because they could allow hackers to take remote control of compromised PCs.

The critical MS05-001 bug uses a handling flaw in HTML to allow malicious third parties to run arbitrary code remotely on unpatched PCs. The vulnerability exists in the HTML Help ActiveX control in Windows.

"If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system," Microsoft warned.

An attacker could then install programs, view, change or delete data, or create new accounts with full privileges.

Users whose accounts are configured to have fewer privileges on the system could be less affected than those who operate with administrative privileges.

The other critical flaw centres on a vulnerability in cursor and icon format handling that could also allow remote code execution.

An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, install programs, view, change or delete data, or create new accounts that have full privileges, according to Microsoft's advisory.

"A remote code execution vulnerability exists in the way that cursor, animated cursor, and icon formats are handled," Microsoft stated.

"An attacker could try to exploit the vulnerability by constructing a malicious cursor or icon file that could potentially allow remote code execution if a user visited a malicious website or viewed a malicious email message."

The third vulnerability, rated as 'important', has been found in the Windows Indexing Service that could allow remote code execution on an affected system. Microsoft pointed out that Indexing Service is not enabled by default on affected systems.

A wide variety of the software giant's consumer and business operating systems are affected by the flaws including Windows 2000, XP (SP2 only patches against one of the critical vulnerabilities) and Windows Server 2003.

Microsoft's security advice can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

28%

1%

13%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Software Developer (.Net, VB.Net) – Skipton

Graduate Developer / Software Developer (.Net, VB.Net...

PHP Developer / Web Developer (PHP4/5, Object Orientated PHP)

PHP Developer / Web Developer (PHP4/5, Object Orientated...

Web Games Designer

Web Games Designer – Gibraltar Web Games Designer...

E-commerce Business / Systems Analyst - retail

An exciting opportunity for a Systems / Business Analyst...

To send to more than one email address, simply separate each address with a comma.