Monday, July 18, 2005

Microsoft Rushes to Fix Critical XP Flaw

I mentioned this late on Friday evening, but Nate Mook writes about a few more details this afternoon in BetaNews:

Microsoft is rushing to patch a critical flaw in the Windows Remote Desktop Service, which affects fully updated Windows XP machines. The problem could be exploited by an attacker to cause a denial of service attack that crashes the PC with a Windows "blue screen of death."

Microsoft was informed of the flaw on May 4, and plans to issue a patch in its August security bulletin. The problem was discovered by Security Protocols, which posted a screenshot of a system being crashed.

"The issue was originally privately reported to Microsoft and we are working on an update that will be released when it is of the appropriate quality," a Microsoft spokesperson said. "The concern is that this has now gone public, potentially putting customers at risk."

Company officials said, however, that there was little risk in code being executed on a remote machine. The DoS attack would simply overload the Remote Desktop service and cause a PC to stop responding.


0 Comments:

Post a Comment

<< Home