Windows Zero-Day Flaw Gets A Fix

Topics Windows Vista, Windows XP on April 11th, 2007

on Tuesday issued five security bulletins with fixes for eight flaws, including a “critical” zero-day vulnerability in that also affects Vista. Four of the security bulletins released as part of ’s monthly patch cycle address problems in . Three are tagged “critical,” ’s highest severity rating, while the other is pegged “important,” a notch lower.

The most serious rating is for bugs that could cause a computer to be fully compromised with little, if any, user action. Among the patches is a fix for a zero-day vulnerability first disclosed in December. Security experts had initially deemed the flaw less serious, stating it could be exploited only by someone with access to a vulnerable computer.

The flaw lies in an essential component called the Client/Server Run-time Subsystem and critically affects all current releases, said in security bulletin MS07-021. “If a user viewed a specially crafted Web site, an attacker who successfully exploited this vulnerability could take complete control of an affected system,” the company said. The MS07-021 update is the only patch released Tuesday that affects Vista.

All of Tuesday’s fixes apply to its predecessor, XP. This includes a critical hole in the Agent, a help tool that succeeded the famous Clippy Office assistant. The Agent flaw also affects 2000 and Server 2003. The Agent is flawed in the way it handles certain specifically crafted Web links.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • StumbleUpon
  • Facebook
  • Google
  • Furl
  • Live
  • MisterWong.DE
  • NewsVine
  • Reddit
  • Slashdot
  • Technorati
  • YahooMyWeb
  • BlinkList
  • description
  • Fark
  • Netvouz
  • Spurl
  • MisterWong
  • Webnews.de
  • e-mail

Tags:, , ,

Related posts

Leave a Reply