Feeds

MS security patch slows XP systems to a crawl

Nasty side effects

  • alert
  • submit to reddit

High performance access to file storage

Microsoft last week attached a health risk to one its own security patches, following widespread complaints that the fix slowed systems to a crawl.

The problematic patch, designed to fix a flaw in the way the kernel passes error messages to a debugger, was issued on April 16. The vuln affects Windows NT 4.0, NT 4.0 Server, Terminal Server Edition, Windows 2K and Windows XP) and is - potentially - very serious.
However the vuln is also difficult to exploit, hence Microsoft's designation the problem as "important" - and not critical.

For an attack to be successful, an attacker would need to be able to logon interactively to the system, either at the console or through a terminal session, Microsoft explains. Servers are less vulnerable to the issue, according to MS, because of commonplace restrictions on the ability to logon interactively.

Once this substantial login hurdle is cleared, all manner of mischief is possible.

"An attacker could exploit this vulnerability to take any action on the system including deleting data, adding accounts with administrative access, or reconfiguring the system," according to Microsoft.

XP users who followed Microsoft's initial advice and applied the patch were in for a nasty surprise.

Reg reader Granville Gough writes: "If you are running WinXP and install this fix, your machine will be compromised. It will slow to a crawl, taking up to 30 seconds to open a spreadsheet, Word doc, run Meidaplayer and more."

"The problem goes away if the fix is removed," he adds.

In a warning, issued on Friday, (Apr 25) Microsoft says it has "investigated this issue and confirmed that there can be performance problems when the patch is applied to Windows XP Service Pack 1 systems.

"Microsoft is actively working on a revised patch for Windows XP Service Pack 1 and will re-issue that patch when it has been completed and fully tested."

However reader Scott Lappin reports that the flaky patch also had "disastrous effects" on Win2K systems, so it seems the performance problems are not isolated to WinXP - contrary to Microsoft's suggestion.

So until Microsoft gets its act together users are left with the choice of leaving their systems vulnerable to an "important" security flaw or applying an exceedingly slow quick fix.

Microsoft's revised advisory fails to clearly recommend either course of action, leaving it to the discretion of users. ®

Related Stories

IT managers trust Microsoft on security...
NT4.0 too flawed to fix - official
Critical Win2K flaw yields multiple attack vectors
Minor glitch in Win2K patch

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.