AfterDawn: Tech news

Criminals target unpatched Windows XP bug

Written by James Delahunty @ 15 Jun 2010 10:43 User comments (5)

Criminals target unpatched Windows XP bug A few days ago, we reported about a controversial disclosure of an exploitable vulnerability that affects Windows XP and Windows Server 2003. Google engineer Tavis Ormandy had alerted Microsoft of the problem and then just five days later published an advisory detailing the bug, even though no patch had been distributed by Microsoft for the problem.
Ormandy was heavily criticized for not waiting until the Redmond software giant had pushed out an update for the bug, which affects the Windows Help and Support Center. His affiliation with Google also fueled some speculation of his motivation for publishing the advisory early. However, Ormandy has consistently defended himself, indicating this is probably the only way to ensure that Microsoft will release a patch.



The flaw was disclosed only last Thursday, but anti-virus provider Sophos has already found that the vulnerability is being targeted by criminal hackers. The bug could potentially allow an attacker to execute code on a victims computer using specially crafted webpages or crafted links in e-mail messages.

While the original bug affects Windows Server 2003, Microsoft's analysis found that only Windows XP is vulnerable to the attacks. Currently, the crafted webpages download an execute malware (Troj/Drop-FS) on a victims computer, according to Sophos.

Microsoft amended its own advisory on the bug, adding that the company is aware that limited, targeted active attacks are happening as a result of the issue.

Windows XP users concerned about the bug can use Microsoft's online FixIt application to disable vulnerable features in the Help and Support Center.

Previous Next  

5 user comments

115.6.2010 22:51

I'm sure MS will get right on this...as soon as their lawyers tell them they have to.

215.6.2010 23:03

The guy who released the code is a serious bitch, who cares about how long Microsoft took to fix the vulnerability at least we know they will get it fixed, its not like they don't have anything else to do lus they already want to drop support for it. Now this idiot has exposed a vast amount of xp users to it which could have been prevent had he not released it with detail. No excuse that was just wrong.

316.6.2010 01:29

"at least we know they will get it fixed"

That is just the thing; microsoft leaves a lot of security holes open for years and years while hackers know about the holes; they patch the easy ones, but the hard ones don't even get fixed for the service packs; in fact some of the security holes in windows 7 have been there since windows 2000, and some even go back to NT4! At least my making a big, public spectacle of the problem, he has forced microsoft to fix the problem...oh wait, it still isn't fixed; they just released a tool to disable features until they fix them...and it isn't even an automatic update. Microsoft should spend less time blaming the person who reported the problem and more time fixing the problem!

416.6.2010 11:40

Originally posted by KillerBug:
"at least we know they will get it fixed"

That is just the thing; microsoft leaves a lot of security holes open for years and years while hackers know about the holes; they patch the easy ones, but the hard ones don't even get fixed for the service packs; in fact some of the security holes in windows 7 have been there since windows 2000, and some even go back to NT4! At least my making a big, public spectacle of the problem, he has forced microsoft to fix the problem...oh wait, it still isn't fixed; they just released a tool to disable features until they fix them...and it isn't even an automatic update. Microsoft should spend less time blaming the person who reported the problem and more time fixing the problem!
Asked you the last time you commented on these security holes, which security hole are you referring to that's been around since NT debuted that still affects Windows 7?

517.6.2010 22:42

Originally posted by Dela:
Originally posted by KillerBug:
"at least we know they will get it fixed"

That is just the thing; microsoft leaves a lot of security holes open for years and years while hackers know about the holes; they patch the easy ones, but the hard ones don't even get fixed for the service packs; in fact some of the security holes in windows 7 have been there since windows 2000, and some even go back to NT4! At least my making a big, public spectacle of the problem, he has forced microsoft to fix the problem...oh wait, it still isn't fixed; they just released a tool to disable features until they fix them...and it isn't even an automatic update. Microsoft should spend less time blaming the person who reported the problem and more time fixing the problem!
Asked you the last time you commented on these security holes, which security hole are you referring to that's been around since NT debuted that still affects Windows 7?
Exactly....please elaborate with facts, or STFU.
MS doesn't make a habit of not patching known security holes, and there are zero NT to W7 cross platform exploits that I'm aware of (that aren't patched), and I've worked in the PC Security industry (Independant analyst/tester).
I think you're just a "bash MS" bandwagon rider myself, willing to float whatever rumor suits your fancy, without ever explaining them.
Sure...everyone knows Windows is a security nightmare, I'll just drop this made up (but plausible sounding) post out there, all the other wagon jumpers will surely line up to rattle the cages even more, and nobody will ever be the wiser...right?

Wrong...this sh!t is getting old really fast. Normal PC users trying to make a name for themselves on forums by being all blustery and flying the bash flag higher than the others. Maybe all of the others will think you're a cool geeky type because you post claims that all the other wagoneers will roll with gleefully without question, but those in the know are sick of this cr@p and are gonna start calling you on this.

Despite what you think, the entire security industry will think this guy is in the wrong by releasing exploit data before a proper fix can be released. The only thing he's "forcing" is the criminals...to exploit as much as they can before a patch is released thru WU.

Now, go burn up Google search trying to find something that can back up your "claims" and get back to us ASAP.
This message has been edited since its posting. Latest edit was made on 17 Jun 2010 @ 10:45

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive