• On MovieTome: CAPTAIN AMERICA was in THE HULK?!?

July 15, 2005 2:23 PM PDT

Windows flaw could spawn DoS attacks

  • Font size
  • Print
Related Stories

PCs falling victim to Windows flaws

July 12, 2005
A newly discovered and as-of-yet unpatched security vulnerability in Windows XP could let an attacker remotely crash computers.

The flaw affects the Windows Remote Desktop Service, which lets users access their Windows PC from a remote location. An attacker could remotely exploit the problem to crash a victim's PC in what's known as a denial-of-service attack, according to a posting on the Security Protocols Web site earlier this week. The user would then see the Windows "blue screen of death."

Microsoft knows of the security flaw and is working on a patch, a company representative said on Friday.

"The issue was originally privately reported to Microsoft and we are working on an update that will be released when it is of the appropriate quality," the representative said. "The concern is that this has now gone public, potentially putting customers at risk."

According to the Security Protocols Web site, Microsoft was informed of the problem on May 4 and plans to release a patch as part of its August update cycle. Fully patched Windows XP machines--including those with the Service Pack 2 update and the firewall enabled--are vulnerable, according to Security Protocols.

In its initial review of the bug, Microsoft found that an attacker would not be able to run code on the victim's PC, but the attacker could cause the computer to stop responding, the representative said. Also, only computers that have the Remote Desktop Service enabled are vulnerable, she said. Windows ships with the service disabled, according to Microsoft.

Security researchers at iDefense are also looking into the vulnerability. "It does not look like it is more than a DoS," said Michael Sutton, a lab director at iDefense. "An attacker won't be able to take over your PC, but could knock it offline."

Security monitoring company Secunia rates the vulnerability "moderately critical," it said in an advisory issued on Thursday.

Microsoft said it is not aware of attacks that try to use the new vulnerability.

Reports of the new Windows flaw come in the same week that Microsoft patched two "critical" Windows vulnerabilities. Both those Windows flaws are actively being exploited by attackers, the Redmond, Wash., software giant said on Tuesday.

See more CNET content tagged:
attacker, iDefense, flaw, denial of service, vulnerability

Add a Comment (Log in or register) 7 comments
so...
by Scott W July 16, 2005 1:00 AM PDT
they get to work on a patch to stop DoS attacks but leave security holes open to worms and other viruses... amazing priorities MS...
Reply to this comment
Why would you leave people at risk Microsoft...
by OneWithTech July 16, 2005 8:55 AM PDT
...knowing that you have a securtiy problem with your operating
system?

Why would you feel it necessary to put millions of PC users at
risk of a DoS attack, in lieu of just patching the problem like you
have been in the past 3 and a half years.

At this point in time you [Microsoft] are knowingly and willingly
putting consumers at risk of damaging important data across
the board, including but not limited to consumers and
corporations alike.

Your laid back approach to security patches that deal with
worms and virus' are convienent to your opperation at the cost
of consumers'. This is a practice that seems evident at Microsoft
over the course of the companies existance.

In retrospect, why would you [Microsoft] think that your next
operating system would show any improvement or gain over the
prevailing OS, XP?

The technologies that you represent in future OS's is that of
"yesterday's news", and have been used by the likes of Apple and
the Mozilla Foundation in previous years.

The be all, end all question is?
It's almost four years Microsoft, over 300 security holes and
counting; how can you improve that in your upcomming
Operating System?

-Justin
Reply to this comment
And we're being told this because...?
by PCCRomeo July 16, 2005 10:14 AM PDT
Due to the major security flaws in Windows, I have come to always expect the worse. I'm not the least bit supprised when a new flaw arises from Windows.
Reply to this comment
the fun bit is
by Scott W July 16, 2005 5:23 PM PDT
the fun bit is that MS do NOT patch security holes UNTIL they are exploited. this is what give OSS the advantage. when someone sees a flaw then a patch is developed and released hopefully before someone can exploit it. MS just say "it hasn't been exploited so we don't need to take action". quite a pathetic attitude. thank god i rely on linux. at least THEY care about the users of their OS.
Is this news?
by July 16, 2005 10:47 AM PDT
seriously dudes...
Reply to this comment
Exploit? Why?
by July 17, 2005 8:44 AM PDT
So a user can crash your PC from across the globe... No need. It crashes from normal usage, why bother to crash it manually?
Thank God for my linux desktop with an uptime of 6 months. Cnet should go out and find some real news like: windows not crashing for an instance (and I don't mean the Microsoft funded 'independent' surveys).
Reply to this comment
Buy a Mac.
by July 17, 2005 11:47 AM PDT
Just get Mac OS X - Tiger. Why punish yourself further.
Reply to this comment

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.00%) 0.00 19.11
Dow Jones Industrials (0.00%) 0.00 8,376.24
S&P 500 (0.00%) 0.00 845.22
NASDAQ (0.00%) 0.00 1,445.56
CNET TECH (0.00%) 0.00 1,045.01
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right