Microsoft releases patch to fix remote code-execution hole
Windows XP and Windows Server 2003 unaffected
May 10, 2005 12:00 PM ETComputerworld -
Microsoft Corp. today released its monthly security update with a patch to repair a newly discovered "important" vulnerability in Windows that can allow remote code execution in Windows Explorer.
Both Windows 2000 Service Pack 3 and Windows 2000 Service Pack 4 are affected by the security bulletin. The vulnerability is not found in Windows XP or 64-bit XP, or in Windows Server 2003 and Server 2003 64-bit operating systems, according to the company.
The vulnerability is in Windows 98/98SE and Windows Millennium Edition, but the company no longer provides security updates for those older operating systems unless they are rated "critical."
Microsoft Security Bulletin MS05-024 said the patch fixes a remote code-execution vulnerability found in Windows Explorer's file management utility. The vulnerability involves the way that Web View in Windows Explorer handles certain HTML characters in preview fields, according to the company.
Microsoft rates the vulnerability as "important," the third-highest level of its four-level Maximum Severity Rating system. The highest level of update importance is "critical."
Stephen Toulouse, a security program manager for Microsoft's Security Response Center, said the vulnerability could allow an attacker to run or install malicious software on a user's computer, or it could allow an attacker to view or delete files remotely.
Such an attack, however, would require user intervention, he said, because a user would have to click to execute and open a file sent by an attacker. "It's not an automated attack," Toulouse noted.
The vulnerability was identified about four weeks ago on a security mailing list, Toulouse said, before Microsoft had an opportunity to create a patch to repair it. Usually, vendors are given notice of such vulnerabilities before they are made public so that fixes can be made ahead of attacks, he said. "We believe it puts people at risk," he said of the public announcement before the patches were made available.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
HP Technology Guide for Scalable Business Solutions
Download This Resource Now!
Enterprise Application Delivery: No User Left Behind
Gain the ability to deliver applications to all users, using any device, across any network.
Gartner: Magic Quadrant for Application Delivery Controllers, 2009
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing...
Data Protection is not an insurance policy -you cannot buy-back lost data
Find out why you need to maintain access to critical information to run your business and remain competitive.
Chiquita selects Workday's fresh approach to Human Capital Management
A fresh approach to meet IT and HR objectives.
ITIL in Tough Economic Times
Are you looking for new inspiration to move forward with ITIL in these tough economic times?
The ROI of Software-As-A-Service
A Total Economic Impact™ Analysis Uncovers Long-Term Value In SaaS
IT Governance Podcast: IT Provider Forecasts $10 Million in Savings
In this podcast, learn how OTS was able to prioritize, then deliver, on the mission-critical demands and, in the process, project $10 million...
