Networking
Security
Telco/ISP
Storage
Hardware
Software
Oddware
Strategy
Finance
Training & Development
Login
|
Join iTnews
|
Sitemap
|
RSS
Reviews
|
Galleries
|
Events
|
Net Seminars
|
Whitepapers
|
Downloads
|
Newsletter
Home
>
News
>
Technology
>
Security
>
Zero-day flaw hits Windows XP
Security
Zero-day flaw hits Windows XP
Related Articles
MWC: Microsoft announces Windows Mobile 6.5
Microsoft unveils Windows 7 Release Candidate
Parallels to offer XP compatibility product for Windows 7
Windows 7 to get XP Mode for compatibility
Breaking Stories
Vale Internode Unwired customers
$62m smart building for RMIT
Telemarketers heed watchdog's call
NICTA GiFi chip takes a gong
Budget limitations stall mobile CRM strategies
By
Shaun Nichols
Sep 20, 2007 7:08 AM
Tags:
Zero-day
|
flaw
|
hits
|
Windows
|
XP
Vulnerabilities in MFC42 and MFC71 could allow remote code execution.
A new zero-day flaw has been reported in a system component of Microsoft's Windows XP.
Experts warned that, depending on the way in which the attack is conducted, the flaw could allow an attacker to execute code on a target system.
The vulnerability lies in two Windows components known as MFC42 and MFC71 which are part of the Windows API that is used by virtually all Windows applications to communicate with the operating system.
When the user opens a document that calls on the function, a condition could be created that leads to a crash and potentially allows an attacker to run malicious code on a user's system, according to
Secunia
.
There is currently no fix for the vulnerability, although Secunia said that the only applications known to access the components are HP's Photo & Imaging Gallery 1.1 and version 2.1 of the software/driver installer for HP's All-In-One series.
Secunia credited the
discovery of the flaw
to researcher Jonathan Sarba of the
GoodFellas Security Research Team
.
The group claimed to have notified Microsoft about the flaw on 21 June, but that it was not until earlier this month that the company acknowledged that it was working on a fix.
A Microsoft spokesperson would not directly comment on the report, but did tell www.vnunet.com that the company is looking into "new public claims of a possible vulnerability in Microsoft Windows".
Secunia classifies the vulnerability as 'moderately critical', the third of its five alert levels.
Administrators looking to minimise risk from the flaw should block user access to applications that use the vulnerable MFC components.
Copyright © 2009 vnunet.com
Email this
Print this
Tweet this
Send us your tips
Comments
Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Register for FREE
Or
log in
now to comment
Ads by Google
Top Stories
Basslink lights up with commercial traffic
Calls for second independent cable.
Bluetooth "Big Brother" tracks festival-goers
Might have retail and security applications.
Huawei considers Australian 4G lab
But dollars depend on demand.
Conroy reveals six regional backhaul winners
ISPs test Basslink cable
Macquarie data centre loses water supply
Microsoft gives TechEd delegates Windows 7 netbook
Leak: Vodafone customers protest poor network
Macquarie data centre loses water supply
Developers get paid for Grocery Choice
Apple agrees to industry standard mobile phone charger
Unwired sees more smartphones using free WiFi
Analysis: Cybercrime spreads on Facebook
Spotlight
the topics we're following
Cloud computing
Internet Filtering
NBN
Data Centre strategy
Virtualisation
Latest Comments
" Erin Kutz wrote: A tiny fraction of those who use the fast-growing social network phenomenon ..."
on
Just a few on Twitter do all the tweeting - study
by
Slatts
Jul 6, 2009 8:58 AM
"I'm thinking there was some robust discussion in the Sawers household when Sir John got home ..."
on
British spy chief's cover blown on Facebook
by
Slatts
Jul 6, 2009 8:41 AM
"Well... that seems disturbing but I just can't seem to put my finger on why. I think it just ..."
on
Aussie firm sells Twitter followers
by
Slatts
Jul 6, 2009 8:35 AM
"I turn bluetooth off on my mobile to save the battery. Looks like now I've got another reason. "
on
Bluetooth "Big Brother" tracks festival-goers
by
Slatts
Jul 4, 2009 1:09 PM
"I'm kind of assuming that the water was used in water cooled condensers for the air-conditioning...."
on
Macquarie data centre loses water supply
by
Slatts
Jul 2, 2009 8:54 PM
Polls
What will you do when your iPhone contract comes up for renewal?
Retain my current service provider
Switch to a cheaper plan
Switch to a better network
Switch to whoever offers free tethering
Change handset altogether
|
View results
Retain my current service provider
11%
Switch to a cheaper plan
17%
Switch to a better network
17%
Switch to whoever offers free tethering
18%
Change handset altogether
36%
TOTAL VOTES: 201
Vote
view previous polls »
Popular Tags
available
beta
browser
candidate
company
fix
flaw
hits
live
microsoft
mobile
operating
patch
release
security
server
system
update
vista
windows