Microsoft releases patch to fix remote code-execution hole
Windows XP and Windows Server 2003 unaffected
May 10, 2005 12:00 PM ETComputerworld -
Microsoft Corp. today released its monthly security update with a patch to repair a newly discovered "important" vulnerability in Windows that can allow remote code execution in Windows Explorer.
Both Windows 2000 Service Pack 3 and Windows 2000 Service Pack 4 are affected by the security bulletin. The vulnerability is not found in Windows XP or 64-bit XP, or in Windows Server 2003 and Server 2003 64-bit operating systems, according to the company.
The vulnerability is in Windows 98/98SE and Windows Millennium Edition, but the company no longer provides security updates for those older operating systems unless they are rated "critical."
Microsoft Security Bulletin MS05-024 said the patch fixes a remote code-execution vulnerability found in Windows Explorer's file management utility. The vulnerability involves the way that Web View in Windows Explorer handles certain HTML characters in preview fields, according to the company.
Microsoft rates the vulnerability as "important," the third-highest level of its four-level Maximum Severity Rating system. The highest level of update importance is "critical."
Stephen Toulouse, a security program manager for Microsoft's Security Response Center, said the vulnerability could allow an attacker to run or install malicious software on a user's computer, or it could allow an attacker to view or delete files remotely.
Such an attack, however, would require user intervention, he said, because a user would have to click to execute and open a file sent by an attacker. "It's not an automated attack," Toulouse noted.
The vulnerability was identified about four weeks ago on a security mailing list, Toulouse said, before Microsoft had an opportunity to create a patch to repair it. Usually, vendors are given notice of such vulnerabilities before they are made public so that fixes can be made ahead of attacks, he said. "We believe it puts people at risk," he said of the public announcement before the patches were made available.
Additional Resources


White Papers & Webcasts
File Integrity Monitoring: Secure Your Virtual and Physical IT Environments
Learn how integrity monitoring software solutions enable IT organizations to achieve and maintain configuration control. Tripwire® Enterprise is the first solution to effectively...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Differentiating With Technical Support: JBoss Customer Support Study
JBoss' expert technical support services is clearly acknowledged by its client base. The comprehensive nature by which their service is unsurpassed. Every category...
IDC Webcast: Linux Adoption in a Global Recession
Join Al Gillen from IDC and Michael Applebaum from Novell in this on-demand webcast to see how Linux has emerged as an even...
The JBoss SOA Assessment Tool: Spend Less, Do More
SOA does not have to be overly complex or expensive. The JBoss SOA Assessment Tool can help you chart a course to a...
Novell Opens PR Video
Is the Linux desktop for me? Customers are looking for ways to be more flexible and save money. Using Linux offers a great...
The CIO's New Guide to Design of Global IT Infrastructure
Is it possible to eliminate the impact of distance? This paper explores the 5 key principles successful CIOs are using to redesign IT...
2 Minutes to IT workload automation
Take just 2 minutes to watch this short CONTROL-M flash video. Well show you how BMC CONTROL-M can put money back into your...
IBM Lotus Notes Performance Brief
This is a Performance Brief that illustrates how Riverbed Steelhead appliances accelerate Lotus Notes R7....
Security Configuration Management
In this web video, follow along with Jim Hansen, Senior Product Manager with Big Fix, as he explains why Security Configuration Management is...
Subscribe to Computerworld
