Microsoft patches flawed, security company claims

By Patrick Gray
26 November 2002 01:10 PM
Tags: security, patrick gray, secunia, advisory, vulnerable, patch
Two security patches recently released by Microsoft do not completely work, according to IT security company Secunia.

In an advisory released last Friday, Secunia have raised doubts over patches accompanying Microsoft Security Bulletins MS02-065 and MS02-066.

The Secunia advisory says that the patch to MS02-065 "...allows an old component to be reactivated - without any warning, thus the vulnerability may still be exploited."

Referring to MS02-066, the Secunia advisory says that the patch was supposed to fix a vulnerability that "...allowed malicious websites to execute executable files in the local security zone".

However according to the Secunia advisory "...what has been closed is another vulnerability, which made it possible to pass arguments to the executable file. It is also still possible to read contents of the clipboard as well as writing new contents to it".

The advisory also makes mention of the fact that "Microsoft has known about these vulnerabilities at least since 22nd October 2002".

Secunia also say that it is "...likely that these vulnerabilities will be exploited on a broad scale soon".

Secunia expect Microsoft to release a revised bulletin.

Microsoft were unable to comment at the time of writing.

Talkback 1 comments

    Who is dumb enough to keep usi ...Jill H. Gates III -- 27/11/02

    Who is dumb enough to keep using Windows when we know what we do about Microsoft’s unethical and illegal business pratices, the crapiness of their Swiss Cheese operating systems / products, especially when there are cheaper and better alternatives in the form of Linux and Mac OS X etc. available today?

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

Tags

Back to top

Featured