Microsoft patches flawed, security company claims

By Patrick Gray
26 November 2002 01:10 PM
Tags: security, patrick gray, secunia
Two security patches recently released by Microsoft do not completely work, according to IT security company Secunia.

In an advisory released last Friday, Secunia have raised doubts over patches accompanying Microsoft Security Bulletins MS02-065 and MS02-066.

The Secunia advisory says that the patch to MS02-065 "...allows an old component to be reactivated - without any warning, thus the vulnerability may still be exploited."

Referring to MS02-066, the Secunia advisory says that the patch was supposed to fix a vulnerability that "...allowed malicious websites to execute executable files in the local security zone".

However according to the Secunia advisory "...what has been closed is another vulnerability, which made it possible to pass arguments to the executable file. It is also still possible to read contents of the clipboard as well as writing new contents to it".

The advisory also makes mention of the fact that "Microsoft has known about these vulnerabilities at least since 22nd October 2002".

Secunia also say that it is "...likely that these vulnerabilities will be exploited on a broad scale soon".

Secunia expect Microsoft to release a revised bulletin.

Microsoft were unable to comment at the time of writing.

Advertisement

Talkback 1 comments

    Who is dumb enough to keep usi ...Jill H. Gates III -- 27/11/02

    Who is dumb enough to keep using Windows when we know what we do about Microsoft’s unethical and illegal business pratices, the crapiness of their Swiss Cheese operating systems / products, especially when there are cheaper and better alternatives in the form of Linux and Mac OS X etc. available today?

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured