Microsoft owns up to latest Windows flaw

It's a day that ends in a 'y' - must be time for a security warning from Gates and Co...

By Robert Lemos, 19 September 2002 10:00

NEWS Microsoft has issued a warning relating to two new critical flaws in its Windows operating system that could allow a malicious attacker to take control of a user's PC. The critical flaws occur in the software giant's implementation of the Java Virtual Machine, which allows platform-independent programs to run on a PC. "[The flaws] could enable an attacker to gain complete control over a user's system," stated the advisory. "This would enable the attacker to perform any operation that the user could, such as running applications; communicating with websites [and] adding, deleting or changing data." An attacker could exploit the flaws by getting the victim to view a certain website with the code embedded in the page. HTML email could also be a danger, unless the recipient uses Outlook 2002, Outlook Express 6.0 or has installed the Outlook Email Security Update. Those who used the Internet Explorer security settings to disable Java applets won't be affected by the vulnerabilities. The first vulnerability is caused by a lack of vigilance of certain Java classes that handle database requests. While the classes do attempt to block illegal requests, the security measures can be bypassed, the advisory states. A second flaw occurs in a Java class that's provided to support the use of XML via Java, but allows all programs - not just a select few - to use the methods. Microsoft has a patch posted on its site and linked from the advisory. Windows users can also get the patch through Windows Update. Robert Lemos writes for News.com

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ