
Microsoft's 48th warning of the year...
By Robert Lemos
Published: 29 August 2002 08:23 BST
Microsoft admitted last night to a critical flaw in most versions of the company's Windows operating system that could allow malicious attackers to corrupt the digital certificates that PCs use to connect to network services.
The vulnerability can be exploited via a special coded ActiveX inserted into hypertext markup language (HTML), the lingua franca of the web. To fall victim to attack, a PC user would have to browse a website, or open an HTML email, specifically set up to take advantage of the vulnerability.
"(The flaw) could enable a web page, through an extremely complex process, to invoke the (ActiveX) control in a way that would delete certificates on a user's system," Microsoft warned in an advisory released late Wednesday.
Such digital certificates are used to hold encryption keys used in email, the encrypted files system (ESS) that is shipped with certain versions of Windows, and in the Secure Sockets Layer communications protocol used by many ecommerce websites. ESS is shipped in Windows 2000 and Windows XP Professional. While the flaw doesn't allow a malicious vandal to steal the certificates, it does allow the attacker to corrupt the data, rendering it useless to the PC's owner.
Depending on the certificates corrupted, the act would prevent the victim from encrypting and decrypting email, encrypting files and complicate the use of secure websites, Microsoft advised. The flaw occurs in the Certificate Enrollment ActiveX Control.
Microsoft suggests that all users of Windows Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000 and Windows XP patch their system immediately.
The latest advisory brings the number of such warnings by the software giant to 48 for the year
Robert Lemos writes for News.com
Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...
Linux Redhat Systems Administrator - Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). Fantastic opportunity ...
You should have experience working with Active Directory, Microsoft exchange, Windows Server 2003, Windows XP and Office 2000/2003. I am looking for ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Momentum Webcast: Assessment and Deployment Best Practices for Windows Vista (Level...
Momentum Webcast: Moving Forward With Windows Vista SP1 (Level 100)
Microsoft Office System Webcast: Tips and Tricks for Office 2008 for Mac: Incredible...
Microsoft Office System Webcast: Compatibility Tips for Office 2008 for Mac and the...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... ZX Spectrum nostalgia, Mac attack, tag a bag… Reader Comments of the Week
Steve Ranger Editor's Blog: Home computing from Acorn, Amiga and Amstrad, to the ZX Spectrum Nostalgia 2.0...