Help for Hackers in latest MS security alert
By Steve Malone
Posted on 3 Oct 2002 at 10:08
Microsoft has alerted users to potentially 'critical' flaws in most flavours of Windows including Windows 98, ME, NT 4.0, 2000 and XP. This time Redmond says there are two problems found in Windows's HTML based Help systems.
The first issue concerns an Active X control within the HTML Help facility. An unchecked buffer in one of the control's functions could be exploited by a web page or an HTML email allowing the attacker to gain access to the system.
Flaws have also been found with shortcuts inside compiled HTML Help (.chm) files. Because these files can perform a wide range of actions on a computer, they are generally said to be well protected. However, vulnerabilities have been found whereby HTML Help wrongly sets the security levels inside the system.
Microsoft says that exploiting these weaknesses would be "complex" involving using HTML mail to deliver a .chm file containing 'shortcut' code to gain control of the system.
Microsoft has published full details and a list of patches in its latest security bulletin.
From around the web
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement
