Microsoft Windows XP SP2 sports dangerous security hole

“Windows XP Service Pack 2 promises to raise the security bar for the sometimes beleaguered operating system. Unfortunately, one of the new features could be spoofed so that it reports misleading information about system security, or worse, lets a malicious program watch for an opportunity to do damage without being detected. The feature is the Windows Security Center, which displays the status of the key elements of your defenses: Firewall, Updates, and Antivirus. If your firewall has been disabled, or your antivirus is out of date, that news will display here. The information is stored in an internal database managed by the Windows Management Instrumentation (WMI) subsystem built into Windows,” PC Magazine reports. “Based on an anonymous tip, we looked into the WMI and the Windows Security Center’s use of it, and found that it may not only be a security hole, but a crater.”

Full article here.

MacDailyNews Take: Windows-only users, had enough punishment, yet? If so, information about smoothly adding a secure Mac OS X machine to your computing arsenal can be found here.

47 Comments

  1. Like I’ve been saying for a the longest time, with every “new and updated” version, Windows OS is NOT like a block of traditional Swiss cheese, its becoming a block of Lorraine Swiss cheese which has smaller but far more greater holes.

  2. How in the world Windows users do not fell duped and scammed and robbed by Microsoft. Change the business field – say a toaster – and it is as if you were still buying and repairing the same old toaster, such a good value, only 10$ (but repairs to damages here and there already run in the thousands) and the same salesman keeps you promising that WHEN you will get your first crispy perfectly grilled slice of bread THEN you will fully realize the marvel you have.

    And oh yes, that water leaking, we promise it will be fixed soon. Oh, it fried your entire electrical system at home 5 times? Gosh, they do not build reliable stuff anymore. You should be proud to have at least the perfect toaster.

  3. The fact that this (continues to) be even a news story, and people are interested in it, is absolutely astounding! Were it not for real, this would be totally unbelievable.

    The fact that MS is still even in the business of producing Windows (of any flavor) is only slightly less comical, and amazing, than the fact that there are still human beings using it and [gasp]still buying[/gasp] it.

    zac

  4. To be fair, it is a little bit stupid to report this as a whole new “vulnerablity.”

    Security experts have been saying it for a while now — if malicious code is able to execute with admin priviledges on your machine, you are toast. You can no longer trust ANYTHING on the machine to report truthfully to you.

    WMI is just one attack vector among a zillion. If I am evil code running locally as an admin, I could also, without too much effort, replace your kernel, your file browser, your task manager, your DLLs, your OS X Frameworks, etc. with modified versions that lie to you about what the system is doing.

    Granted, the condition — with admin priviledges — is a little tougher on a good platform like OS X where it’s going to ask even an admin user to authenticate before modifying the system.

  5. Question:

    Why didn’t Microsoft release a fix for 95, 98, ME, or 2000?

    There are still plenty of users of those OS’s out there – unless they upgrade to XP, they are still vulnerable.

  6. Here we are 2 years and 7 months after I switched my business from Windows (98, ME, 2000, NT) to OSx.

    That’s 2 years and 7 months without a virus, without data loss, without lost time, without having to re-install the operating system and without the stress of wondering if the d*mn computer will work TODAY.

    Thank you Apple.

  7. That’s funny, our business is rebuilding our NT 4 server after a massive hd crash. Good thing we keep back up tapes! Apparently the mirroring software to keep the second hd backed up failed 2.5 years ago, but nt never gave us a warning message, so we lost a hd full of data and had a back up hd with data that was 2.5 years old…lot of good that was.

  8. STUPID PC USERS, YOU GET WHAT YOU PAY FOR

    I don’t give a ratts arse if they never switch, they are stupid and deserve the punishment of being born idiots.

    I’m a elitist, a Mac User and the rest can go to bloody hell!!!

    < b>HAHAHAHAHAA</b>

  9. Yeah, I admit, I wanna spend 3k on a Powermac. That is a lot of money for a computer. At work we all have 500-700 dollar Dells – decent, if you don’t mind having to force quit (or whatever they call it in Windows) Illustrator, Photoshop, and Indesign every night before I go home. And my company pays some guy 1200 dollars a month to manage our network – a network which is constantly down, unable to connect us to the internet or email and seems to delete files and folders for no apparent reason…
    I’ll stick to my 3k dollar Powermac.

  10. …beleaguered operating syste

    The B-word! And it is used for something other than Apple. Wonder never ceases. ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  11. I got a bad ass Dual 2.5 Ghz G5 which is faster than a Dual 4 Ghz Pentium.

    I got 2 big bad 23″ Displays, soon to get 2 30″ Displays.

    I got a FUll 8 GB of top notch CLI-3 RAM from Crucial

    I got the ATI 9800 Pro, soon to get the Nvidia 6800 ULTRA (with cute mermaid to jack off too)

    I got a RAID INSIDE my G5 and one OUTSIDE YES A APPLE X-RAID with 400 MB PER FRIGGING SECOND WRITES

    I GOT TV CARD, GAMES UP THE WAZZO AND FRAG ALL PC USERS ONLINE.

    I EVEN GOT A T-1 LINE!!!

    PC USERS GROVEL AT MY MACHINE HEADS HUNG IN SHAME

    Now go back to your cheap Dells and crappy WIndows, you poor pathetic fckwads!!!

    Sincerly

    Bill Gates

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.