Feeds

MS probes Win XP SP2 kernel bug

Crash risk dummy

  • alert
  • submit to reddit

Intelligent flash storage arrays

Windows XP SP2 has proved to be a lot more robust than critics give Microsoft credit for but that doesn't mean it's immune from security problems. Security researcher Tom Ferris of Security-Protocols.com discovered a bug in XP's kernel that might be used by hackers to crash even fully patched systems with Windows firewall switched on.

The vulnerability stems from a flaw in Remote Desktop Services (disabled by default except on Windows XP Media Center Edition). A maliciously constructed RDP (Remote Desktop Protocol) request might be used to mount denial of service attacks but Ferris said the bug doesn't lend itself to injecting hostile code into vulnerable systems. Microsoft has confirmed the vulnerability but says the risk is limited to denial of service attacks. "We have not been made aware of attacks that try to use the reported vulnerability or of customer impact at this time, but we are aggressively investigating the public reports," it added.

Nonetheless security alert notification firm Secunia rates the bug as "critical". Seperately, Secunia last week also posted info on another Windows XP SP2 security bug. It warns that a flaw in a Windows Network Connections Service component (netman.dll) also poses a denial of service risk but this is only applies to local users not remote attackers hence a much reduced security risk. ®

Related stories

Firefox update completes busy patching day
Three critical fixes in MS July security update
MS issues final software update for Win2K
10 vulns - three critical - in MS patch batch
MS debuts 'forthcoming attractions' pre-alert alert

Internet Security Threat Report 2014

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.