Welcome Guest ( Log In | Register )

  Recent Tech News
JVC preps dual DVD/Blu-ray disc
Santy Worm Moves On
EBay to Drop Support for Microsoft'...
Microsoft, Citrix Sign Collaboratio...
AOL gets ready to launch free Web e...
  Recent Gaming News
Electronic Arts to buy into Ubi Sof...
Halo 2, San Andreas key drivers of ...
Sony Says All Systems Go for PSP La...
Nvidia to work on PlayStation 3 chi...
New Command & Conquer Game Unveiled
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
Windows XP Sp2 Problems
Leadtek A350XT TDH and overclo...
FX5900U vs 9800Pro
Google Gmail Invites
Doom 3 SDK Released
  Announcement
Welcome to the new AusPCWorld



> AusPCWorld > Tech News > Microsoft posts critical configuration patch






   
Microsoft posts critical configuration patch
Posted by mitchy_g on 20 Dec 2004 - 00:40 0 comments
Previous Post | Tech News | Next Post
 
Microsoft released a "critical" fix on Thursday for a security issue left unresolved by the Windows XP Service Pack 2.

The configuration change closed a hole in the Windows firewall settings that could open up PCs to attack if the machines had been set to share files or a printer with the local network, said Gary Schare, director of product management for Windows.

"The firewall that we shipped in Service Pack 2 was much better than before, but security could be tightened even further," he said. "We told people (in September) that we would issue a software update and now we have."

The hole could allow anyone to access a PC that has its file sharing exceptions set up in the Windows XP SP2 firewall. The problem affects only those who use dialing software to connect to the Internet, Microsoft indicated in a Knowledge Base article on its Web site.
Microsoft did not classify the configuration issue as a software vulnerability and so did not distribute the configuration update with the patches it released earlier this week, Schare said. In fact, the security group did not handle the issue; the Windows product group did.

"We didn't do as good a job as we intended getting this out," he said. "This fell between the teams. The security team said it wasn't a vulnerability, so we don't handle it, and the product people said they are not used to meeting the monthly update schedule."

News source: CNET



There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments




Add A new comment
Sorry, you cannot comment to this news post because you do not have permission to do so.