Microsoft
Microsoft

Experts warn not to apply Microsoft patch

Security companies find dubious content in Windows 2000 fix

Written by James Middleton

Microsoft yesterday released details of yet another vulnerability in versions of Windows, but some security experts are dubious about the contents of the patch for Windows 2000.

The flaw in question is in the Windows kernel and affects XP, NT and 2000. Labelled as 'important', the bug affects the way the kernel passes error messages to a debugger.

It means that an attacker could write a program to exploit the flaw and run code of their choice or take any action on the system including deleting data, adding accounts with administrative access, or even reconfiguring the machine.

But, although a patch has been issued, security experts have recommended users to avoid applying it because it contains a number of unidentified files for which no information is available.

Bronek Kozicki, of Polish security firm Rubikon, and Russ Cooper, of security mailing list NTBugTraq, have both advised that users should not install the Win2k patch until Microsoft releases further details.

"The Windows 2000 version of [this advisory] contains numerous files not listed in the manifest supplied in [the Microsoft Knowledge Base article]," said Cooper.

He listed 10 recently modified files in the patch for which details are not included. This included Ntdll.dll, which was previously included in a fix for a vulnerability discovered on 17 March 2003 (MS03-007) that has been confirmed as causing problems with certain system configurations.

"As has been previously reported, there are definitely problems installing MS03-007 on systems which had previously applied a Product Support Services supplied hot fix," said Cooper.

"If Microsoft has somehow fixed the problems with MS03-007, it has never said so.

"I would strongly suggest that you avoid applying the latest patch [MS03-013] unless you are able to test it in a non-production environment, and possibly wait until Microsoft provides some form of clarification.

"Both the Security Bulletin and Microsoft's Knowledge Base article are incorrect in stating that they do not supersede any other hot fix, as clearly this is not the case for Windows 2000 systems."

More information is available from Microsoft here.

Tags:

reader comments

related articles

Passport flaws exposed users' details

Media Player also under attack 08 May 2003

 

Microsoft releases critical patches

Serious problems in Internet Explorer and Outlook 24 Apr 2003

Flaw hits NT 4, Windows 2000 and XP

'Important' RPC flaw cannot be patched on NT 4, warns Microsoft 28 Mar 2003

Service Pack glitch causes system slowdowns

Windows XP SP1 update flaw affects memory-allocating programs 28 Mar 2003

Microsoft WebDAV flaw causes alarm

Security vulnerability more serious than first thought, warns research 25 Mar 2003

Microsoft issues 'critical' advisory

JScript vulnerability could allow a hacker to embed code in a specially designed web page 20 Mar 2003

Microsoft fixes 20 security flaws

Four 'critical' patches in monthly update 15 Oct 2008

Hackers attack IE7 flaw

Exploit code out within days of patch 18 Feb 2009

Warning of new Windows worm

New botnet being built, say security experts 03 Dec 2008

related whitepapers

today's top stories

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Government aims to bolster UK's cyber defences

Is the UK’s first national cyber security strategy up to the task of co-ordinating the country’s response to digital threats? Computing investigates 02 Jul 2009

Focus resources on what really matters

IT has become too caught up in the drive for efficiency, at the expense of business success 02 Jul 2009

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation