All the latest UK technology news, reviews and analysis

Windows 2000 flaw highlights slow Patch Tuesday

by Shaun Nichols

More from this author

12 Sep 2007

Be the first to comment

  • Tweet this
Microsoft

Microsoft issued four security fixes in its September security bulletin, also known as 'Patch Tuesday'.

Just one of the four flaws was rated as 'critical', Microsoft's highest threat level. The remaining three were given the second-highest rating of 'important'.

The 'critical' patch affects users of Windows 2000 Service Pack 4. The vulnerability lies in the Microsoft Agent component of the operating system.

Attackers could exploit the vulnerability through a specially crafted URL, allowing them to execute code with the privileges of the current user.

Experts downplayed the risk of the vulnerability, which does not affect Windows XP or Vista.

"We do not foresee a lot of exploitation of the Windows 2000 vulnerability," said Dave Marcus, security research and communications manager for McAfee.

"Not many people will use those legacy systems to surf the web, which would be the primary attack vector."

XP and Vista users will, however, see at least one update. A flaw in Windows Services 3.0 for Windows could leave the door open for an attacker to gain elevated privileges on a target system.

Microsoft also patched a code execution vulnerability for MSN and Windows Live Messenger which could allow an attacker to execute malicious software on a user's system by way of a specially-crafted video chat invitation.

Although it could allow for remote attacks, the flaw is likely to yield little fruit for attackers and malware authors, according to Marcus.

"Microsoft forces an update, so there is little chance of actually exploiting this vulnerability," he said.

The fourth patch in the monthly update addresses a vulnerability in Microsoft's Visual Studio development tool. An attacker could remotely execute code on a target machine by convincing a user to open a specially-crafted RPT file.

Microsoft's next security update is scheduled for 9 October.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

UK Based Channel Sales Executive - Security and Service Assuran

UK Based Channel Sales Executive - Security and Service...

Graduate Developer - Manchester

Graduate Developer - Manchester. My client has an opening...

.Net Graduate Developer - Manchester

.Net Graduate Developer - Manchester. My client is looking...

Accounting Business Analyst/ Systems Accountant Bank London

Accounting Business Analyst/Systems Accountant (Back...

To send to more than one email address, simply separate each address with a comma.