Microsoft
Microsoft

Experts warn not to apply Microsoft patch

Security companies find dubious content in Windows 2000 fix

Written by James Middleton

Microsoft yesterday released details of yet another vulnerability in versions of Windows, but some security experts are dubious about the contents of the patch for Windows 2000.

The flaw in question is in the Windows kernel and affects XP, NT and 2000. Labelled as 'important', the bug affects the way the kernel passes error messages to a debugger.

It means that an attacker could write a program to exploit the flaw and run code of their choice or take any action on the system including deleting data, adding accounts with administrative access, or even reconfiguring the machine.

But, although a patch has been issued, security experts have recommended users to avoid applying it because it contains a number of unidentified files for which no information is available.

Bronek Kozicki, of Polish security firm Rubikon, and Russ Cooper, of security mailing list NTBugTraq, have both advised that users should not install the Win2k patch until Microsoft releases further details.

"The Windows 2000 version of [this advisory] contains numerous files not listed in the manifest supplied in [the Microsoft Knowledge Base article]," said Cooper.

He listed 10 recently modified files in the patch for which details are not included. This included Ntdll.dll, which was previously included in a fix for a vulnerability discovered on 17 March 2003 (MS03-007) that has been confirmed as causing problems with certain system configurations.

"As has been previously reported, there are definitely problems installing MS03-007 on systems which had previously applied a Product Support Services supplied hot fix," said Cooper.

"If Microsoft has somehow fixed the problems with MS03-007, it has never said so.

"I would strongly suggest that you avoid applying the latest patch [MS03-013] unless you are able to test it in a non-production environment, and possibly wait until Microsoft provides some form of clarification.

"Both the Security Bulletin and Microsoft's Knowledge Base article are incorrect in stating that they do not supersede any other hot fix, as clearly this is not the case for Windows 2000 systems."

More information is available from Microsoft here.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Passport flaws exposed users' details

Media Player also under attack 08 May 2003

 

Microsoft releases critical patches

Serious problems in Internet Explorer and Outlook 24 Apr 2003

Flaw hits NT 4, Windows 2000 and XP

'Important' RPC flaw cannot be patched on NT 4, warns Microsoft 28 Mar 2003

Service Pack glitch causes system slowdowns

Windows XP SP1 update flaw affects memory-allocating programs 28 Mar 2003

Microsoft WebDAV flaw causes alarm

Security vulnerability more serious than first thought, warns research 25 Mar 2003

Microsoft issues 'critical' advisory

JScript vulnerability could allow a hacker to embed code in a specially designed web page 20 Mar 2003

Security experts highlight spear phishing dangers

Client-side vulnerabilities the biggest risk, warns Sans report 15 Sep 2009

Microsoft set for small Patch Tuesday

Just one fix to be issued next week 08 Jan 2010

Patch Tuesday brings fixes and warnings

Microsoft issues new advisory on IE attacks 10 Mar 2010

related whitepapers

today's top stories

Telepresence: coming to a screen near you?

Telepresence systems enable organisations to hold boardroom-style meetings with far-flung participants without the hassle and expense of arranging travel and accommodation. But while the technology is impressive, it does not come cheap, as Martin Courtney discovered when he sat in on a virtual meeting with executives from Philips 10 Mar 2010

Users give their verdict on Azure

Some of the first wave of UK adopters met in London recently to air their views on Microsoft’s cloud computing platform. Dave Bailey listened in 10 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Martin CaveComment

Lessons to be learned from cricket's internet outing

Imagine the scene. It’s the final of one of the most popular sporting events in the Indian subcontinent and millions of people are glued to their laptops and PCs in anticipation of the four runs required off the last ball of the match. Suddenly the connection jitters and 20 seconds later you see the jubilant crowd flooding onto the field of play… 12 Mar 2010

Wayne GibbonsComment

Social networks are key to cracking China

Business social media can unlock the door to the world’s second-largest economy 10 Mar 2010

Primary Navigation