Topic: Microsoft Issues Security Patch... Before OS is released  (Read 2583 times)

0 Members and 1 Guest are viewing this topic.

Offline Dracho

  • Global Moderator
  • Rear Admiral
  • *
  • Posts: 18289
  • Gender: Male
Microsoft Issues Security Patch... Before OS is released
« on: January 19, 2006, 10:01:01 am »
Does this mean Vista is basically XP in a tuxedo?

Microsoft Issues First Vista OS Patch Walaika K. Haskins, newsfactor.com
Wed Jan 18, 5:05 PM ET
 


Microsoft has issued a security patch for it's as-yet-unreleased operating system, Windows Vista. The patch, issued over the weekend, repairs the same graphics-rendering flaw discovered in Windows XP late last month.

Using the vulnerability, hackers could gain remote access to PCs and install malicious software on them. The flaw, which was called "extremely critical" by several security vendors, affects systems running Windows XP as well as Windows Server 2003.

Currently available to Microsoft developers and beta testers, the technology preview of Vista shared the same vulnerability found in XP. Vista is not slated to be released to the public until later this year.

Microsoft issued the patch for the Vista beta with a warning that the new operating system is vulnerable to the same remote-code execution flaw found in XP.

Widespread Flaw

The fix corrects how Windows Vista handles graphics in the Windows Meta File (WMF) format. While Windows contains routines for displaying these files, a lack of input validation in one of the routines could result in a buffer overflow that would subsequently allow hackers to run code from remote locations.

Graham Cluley, senior technology consultant with Sophos, said the WMF flaw is "extremely serious" and is actively being exploited by many hackers. One indication of the serious nature of the threat, according to Cluley, was one third-party researcher engineering and distributing his own patch while awaiting the security fix from Microsoft.

Another significant indicator was the January 6 release of an official patch from Microsoft, a full week before it was originally slated to be distributed to the public. Microsoft explained it had completed testing earlier than expected and that it was responding to customer requests to release the patch as quickly as possible.

"Now that an official patch is available and has been deployed by many people, we have seen a dramatic tail-off in attempts by criminals to make use of the vulnerability," Cluley reported. He added this recommendation: "Our advice to home users and companies is to waste no time applying this patch on their computer systems."

Better Late Than Never

The week-long wait from the January 6 patch release for Windows XP and Windows Server 2003 to last weekend's issuance of a fix for Vista is understandable, said Cluley, because Vista has not yet hit store shelves and it was not as high a priority for Microsoft engineers.

"It has obviously taken longer for Microsoft to release a patch for the WMF flaw on the Vista platform than current versions of Windows, but that's because Vista isn't yet released and it was a higher priority to protect the shipping versions of Windows," he said.

In the long run, Microsoft would have had to repair the problem anyway to avoid the kind of negative publicity that would hinder sales at the Vista launch, Cluley said.

"They were right to patch Vista, as it would be very poor publicity for the new operating system if it had eventually shipped with flaws that had been fixed in its predecessor months before," Cluley pointed out.

Other Priorities

Although Windows XP and other shipping versions of Windows are top priority for Redmond's engineers, Microsoft has announced that it is delaying the release of the third service pack for Windows XP. According to information posted on Microsoft's site, Service Pack 3 will not be released until the second half of 2007.

The 2007 date puts the introduction of the new service pack well beyond the planned launch of Windows Vista. The company has refused to enumerate what features and patches might be included in the upcoming service pack, but speculation has been running rampant since the release of Service Pack 2 in August 2004.

"We will be releasing another service pack for XP over the course of the product life cycle, and we are tentatively targeting the second half of 2007 for release," a Microsoft spokesperson was quoted in news reports as saying. "However, right now our priority is Windows Vista. We'll have more information to share about the next service pack for XP after Windows Vista ships."

The worst enemy of a good plan is the dream of a perfect plan.  - Karl von Clausewitz

Offline Mr_Tricorder

  • 3D modeler /animator
  • Hot and Spicy
  • Lt. Commander
  • *
  • Posts: 1040
  • Gender: Male
  • Trekkie at Large
    • My myspace page
Re: Microsoft Issues Security Patch... Before OS is released
« Reply #1 on: January 19, 2006, 10:55:45 am »
The more I hear about Vista, the less impressed I am.

I've been hearing this story for a few days now.  I agree with the arguments against this being an intentional backdoor, but I'm not altogether convinced that it was an honest mistake, either.

Offline Dracho

  • Global Moderator
  • Rear Admiral
  • *
  • Posts: 18289
  • Gender: Male
Re: Microsoft Issues Security Patch... Before OS is released
« Reply #2 on: January 19, 2006, 11:03:01 am »
The more I hear about Vista, the more I think of Windows ME.  It sounds like a product they are releasing, just so they can release a product.
The worst enemy of a good plan is the dream of a perfect plan.  - Karl von Clausewitz

Offline Mr_Tricorder

  • 3D modeler /animator
  • Hot and Spicy
  • Lt. Commander
  • *
  • Posts: 1040
  • Gender: Male
  • Trekkie at Large
    • My myspace page
Re: Microsoft Issues Security Patch... Before OS is released
« Reply #3 on: January 19, 2006, 04:32:47 pm »
The sad thing is that ME was released only one year after 98SE and one year before XP and it was obvously a rushed product with relatively little thought put into it, while Vista has been in development for years and is long overdue.  It's been over four years since XP was released, and their not planning on releasing Vista for almost a full year from now, and with the way things are going, that might get pushed back even further.  Yeah, I know they had to scrap a lot of work and start fresh when it was still called Longhorn, but that's no excuse.  It would be nice to have a modern version of Windows that didn't require tons of updating and security software to be installed before it could safely connect to the internet.

Offline Just plain old Punisher

  • Vice Admiral
  • *
  • Posts: 36927
  • Gender: Male
  • I'm not facist, I just like wearing jackboots
Re: Microsoft Issues Security Patch... Before OS is released
« Reply #4 on: January 19, 2006, 07:08:42 pm »
Eh, I'm happy with XP. It's a stable product IMHO. I don't have to format and reinstall every 3 months.

"Sex is a lot like pizza.  If you're not careful you can blister your tongue". -Dracho

Offline Nemesis

  • Captain Kayn
  • Global Moderator
  • Commodore
  • *
  • Posts: 13067
Re: Microsoft Issues Security Patch... Before OS is released
« Reply #5 on: January 19, 2006, 08:38:36 pm »
Microsoft has issued a security patch for it's as-yet-unreleased operating system, Windows Vista. The patch, issued over the weekend, repairs the same graphics-rendering flaw discovered in Windows XP late last month.

Windows Vista is in beta testing.  Beta testing is about finding and patching flaws.  The only thing surprising here is Microsoft patching the existing beta version rather than waiting for the next beta release.  For patching it quickly rather than risking the beta testers security kudos to Microsoft.
Do unto others as Frey has done unto you.
Seti Team    Free Software
I believe truth and principle do matter. If you have to sacrifice them to get the results you want, then the results aren't worth it.
 FoaS_XC : "Take great pains to distinguish a criticism vs. an attack. A person reading a post should never be able to confuse the two."

Offline Just plain old Punisher

  • Vice Admiral
  • *
  • Posts: 36927
  • Gender: Male
  • I'm not facist, I just like wearing jackboots
Re: Microsoft Issues Security Patch... Before OS is released
« Reply #6 on: January 20, 2006, 02:51:43 am »
Some people, with their high standards! Sheesh!

They should bring in morbo to crush the puny pathetic bugs!


"Sex is a lot like pizza.  If you're not careful you can blister your tongue". -Dracho