IDNetters Forums

Technical News & Discussion => Windows News & Discussion => Topic started by: Gary on Jan 05, 2011, 11:00:05

Title: Microsoft confirms code execution bug in Windows
Post by: Gary on Jan 05, 2011, 11:00:05
Quote "Microsoft has confirmed reports that several versions of Windows are vulnerable to exploits that allow remote attackers to take full control of users' computers using booby-trapped emails and websites.

In an advisory issued Tuesday, Microsoft said it was investigating "new public reports" of vulnerability in the XP, Server 2003, Vista, and Server 2008 versions of Windows. In fact, the first known report of the bug in the way those operating systems process thumbnail images came on December 15 at a security conference in South Korea. On Tuesday, exploit code was added to the Metasploit software framework for hackers.

"This is a remote code execution vulnerability," the Microsoft advisory stated. "An attacker who successfully exploited this vulnerability could take complete control of an affected system."

http://www.theregister.co.uk/2011/01/04/windows_0day/
Title: Re: Microsoft confirms code execution bug in Windows
Post by: Rik on Jan 05, 2011, 11:10:22
Will it ever end?
Title: Re: Microsoft confirms code execution bug in Windows
Post by: Simon on Jan 05, 2011, 11:22:06
Never!

:sigh:
Title: Re: Microsoft confirms code execution bug in Windows
Post by: Rik on Jan 05, 2011, 11:35:16
Indeed.
Title: Re: Microsoft confirms code execution bug in Windows
Post by: pctech on Jan 05, 2011, 12:32:37
XP will be 10 years old this October, you'd have thought after 10 years of Quick Fix Engineering hotfixes then it would be pretty robust by now wouldn't you?

Title: Re: Microsoft confirms code execution bug in Windows
Post by: Rik on Jan 05, 2011, 12:33:57
You would. I hope MS don't write the code for Boeing!
Title: Re: Microsoft confirms code execution bug in Windows
Post by: pctech on Jan 05, 2011, 12:36:18
No thankfully not.
Title: Re: Microsoft confirms code execution bug in Windows
Post by: Gary on Jan 05, 2011, 12:51:05
Quote from: pctech on Jan 05, 2011, 12:32:37
XP will be 10 years old this October, you'd have thought after 10 years of Quick Fix Engineering hotfixes then it would be pretty robust by now wouldn't you?


I think the problem is that times and exploits have also changed and a 10 year old OS is probably not the most secure to use now, note Windows 7 is not in the list.
Title: Re: Microsoft confirms code execution bug in Windows
Post by: Rik on Jan 05, 2011, 12:51:51
Neither is Linux. ;)
Title: Re: Microsoft confirms code execution bug in Windows
Post by: Gary on Jan 05, 2011, 12:54:27
Quote from: Rik on Jan 05, 2011, 12:51:51
Neither is Linux. ;)
Or OS X  ;) but XP is now very long in the tooth, people I think should be running windows 7 to be up to date, and safer really.