'10 new Windows XP SP2 flaws' revealed

Jo Best, silicon.com
15 November 2004 08:22 AM
Tags: sp2, flaw, xp, finjan, microsoft, windows xp, vulnerable, claim
A security company has warned that hackers can silently and remotely take over any Windows XP SP2 machine, but Microsoft has rubbished the claims.

According to Security firm Finjan, the flaws mean that "attackers can silently and remotely take over an SP2 machine when the user simply browses a web page".

Finjan has informed Microsoft of the flaws and is working with the Redmond, Washington-based giant to sew them up. The company won't provide any details about the flaws, which have yet to be patched, in case it helps hackers and virus writers start work on exploiting the vulnerabilities before Microsoft issues any potential fix.

However, Finjan did give details of what kind of attack the flaws could be used to launch.

One, according to the company, would allow hackers to remotely access users' local files and another flaw could let hackers bypass XP SP2's notification mechanism about downloading and execution of .exe, which could let them download files without warning the user.

Microsoft, however, isn't hitting the panic button just yet.

A Microsoft spokeswoman said "Microsoft is aware of the claims by Finjan Software of possible vulnerabilities in Windows XP SP2. At this time, Microsoft cannot confirm Finjan's claims of 'ten new vulnerabilities' in Windows XP SP2. Moreover, Microsoft is currently unaware of active attacks against customers attempting to utilise the alleged vulnerabilities as reported by Finjan."

"Our early analysis indicates that Finjan's claims are potentially misleading and possibly erroneous regarding the breadth and severity of the alleged vulnerabilities in Windows XP SP2," she added.

Microsoft is investigating the claims and will issue a fix if necessary.

Advertisement

Talkback 2 comments

    When are computer user getting an operating system that does not require constant updates or a high level of technical expertise.Anonymous -- 15/11/04

    When are computer user getting an operating system that does not require constant updates or a high level of technical expertise.

    SP 2 FlawAnonymous -- 18/04/06

    To whom it may concern,
    I've done some independent tests of my own, and I'm in arrogance with Finjan and it's a couple of years and several computers later and the exact same results show up each computer I used had became unstable (though at one time I wasn't using the icf I was using outpost pro and it ran perfect until the hard drive died on me, that was with XP home SP1)to such a degree that the computer became non-usable, even the current computer I'm currently using has the exact same symptoms:(.

Add your opinion


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured