Windows XP SP2 flaw complex but dangerous

Dan Ilett, Special to ZDNet

02 December 2004 09:14 AM

Tags: security, sp2, windows, flaw, xp, exploit, bypass, setting

Security experts have identified a modified exploit that can target computers running Windows XP SP2.

Although the exploit is tricky to perform, it combines two vulnerabilities in Internet Explorer 6 with a series of ActiveX exploits to break security settings in computers running SP2. It runs when a user moves a file or an image from one part of a Web page to another, but in the process the exploit downloads code to machines that circumnavigates Local Computer security settings in SP2.

Researchers at Danish security company Secunia have labelled the vulnerability as "highly critical" because it allows hackers to access local resources and bypass security features in Windows XP SP2.

"This is the most serious vulnerability for SP2 that we have the moment," said Thomas Kristensen. "The problem is that by exploiting this vulnerability in IE it's possible to drag a file into the local security zone and change the settings. On an SP2 system, this shouldn’t be a problem, but it is still possible to bypass the security with an Active X control."

The company pointed out that Windows XP SP2 does not run Active Scripting in the Local Computer zone, but by performing a series of Active X exploits it is possible to bypass those setting in SP2.

"It's a series of events you have to perform before you are able to bypass security settings," said Kristensen. "It is complicated. But they are several minor issues that can be compromised so it's possible to circumnavigate the security settings."

Kristensen added that SP2 was supposed to tightly lock down the security issues with IE 6, but this was clearly a compromise in it security. He said that the solution was to disable the drag-and-drop or copy-and-paste options on Internet Explorer and set the security level to "high" in the Internet zone.

Advertisement

Talkback 2 comments

  1. Service Pack 2 is no better. In my experience with service pack 2 I would not recomend it at all. For starters I have been hacked through 2 firewalls within 3 days of a rebuild to go to service pack 2. The security features are a night Anonymous -- 02/12/04

    Service Pack 2 is no better.

    In my experience with service pack 2 I would not recomend it at all.

    For starters I have been hacked through 2 firewalls within 3 days of a rebuild to go to service pack 2. The security features are a nightmare for gamers who want to tweak performance by disabling certain services and apps.

    Typical Microsoft rubbish, Once agin they are not thourough in their work.

    I personally dont care hiow many lines of code ther are as it is irrelavant, they just need to make it safe no matter what and not release it untill it works with feature which suit all situations.

  2. I made a big mistake last year letting my Norton Internet Security expire because I thought Microsoft was enough protection and I ended up hiring a local technician to clean my disk which was infected with 47 viruses. Now I have Norton firewall working. Anonymous -- 03/12/04

    I made a big mistake last year letting my Norton Internet Security expire because I thought Microsoft was enough protection and I ended up hiring a local technician to clean my disk which was infected with 47 viruses. Now I have Norton firewall working. It seems to block everything that it considers an intrusion. My question is about gaming. Everytime I download a game from Real Arcade I am getting a HIGH RISK warning from Norton's program about the WELCHIA WORM SCAN. I used the tracking feature and it tracked it back to an address in Washington State. This keeps happening over and over. What is this? And should I worry about it?

Add your opinion


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured