iTnews
  • Home
  • News
  • Technology
  • Security

Microsoft warns of zero-day Windows Shell flaw

Staff Writer
Jul 20 2010 12:25PM
Follow google news

XP SP2 users again urged to upgrade.

Microsoft has issued IT managers with a new advisory concerning the security of its Windows operating system.

So far the firm is only investigating reports of the vulnerability, which it said could affect a range of Windows products.

Microsoft explained in a security advisory that the vulnerability is caused by the way Windows parses shortcuts.

The firm added that the operating system does this "in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut".

The list of possibly susceptible systems includes Windows XP Service Pack 3, Windows Vista Service Pack 1 and Service Pack 2, and Windows 7 for 32-bit and 64-bit systems, but not XP Service Pack 2 or Windows 2000.

The fact that the last two are not mentioned drew the attention of Wolfgang Kandek, chief technology officer at security company Qualys, who suggested that this might cause more problems.

"Microsoft ended support for both operating systems last Tuesday," he said. "We assume the attack works against both of them, and attackers will surely take advantage of this security hole," he said in a blog post.

"We recommend upgrading your existing Windows XP SP2 installations to SP3 as soon as possible."

Companies still using Windows 2000 would face a "bigger hurdle", Kandek added, as this would require them to upgrade their operating system wholesale if they are to avoid falling foul of the bug.

Microsoft admitted that it is investigating reports of exploits already being used, and warned that, if an attack is successful, the miscreant responsible would be able to take over user rights on the computer.

In the absence of a security patch, which could follow shortly, Microsoft has released information on workarounds.

Microsoft warns of zero-day Windows Shell flaw

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
operatingpacksecurityservicesoftwarewindowsxp

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.