News
News
1/17/2006
09:28 AM
50%
50%

Microsoft Posts First Windows Vista Security Fix

The patch fixes a bug in how Windows' graphic rendering engine processes Windows Meta File images.

Microsoft on Friday released the first security update for Windows Vista, the Redmond, Wash.-based developer's next-generation flagship OS that's touted as ultra secure.

The patch fixes a bug in how Windows' graphic rendering engine processes Windows Metafile (WMF) images. That bug was first discovered in late December 2005 and was quickly exploited by hackers to infect systems with spyware, adware, and other malicious code.

The Jan. 5 out-of-cycle WMF security fix from Microsoft didn't--and still doesn't--list Vista among the flawed, but with the posting of patches it's clear that the same "SetAbortProc" function at the root of the WMF bug exists in Vista.

In the update documentation Microsoft said only that "A remote code execution security issue has been identified in the Graphics Rendering Engine that could allow an attacker to remotely compromise your Windows-based system and gain control over it." That language, however, closely matches what Microsoft wrote in its MS06-001 security bulletin, where it said "a remote code execution vulnerability exists in the Graphics Rendering Engine because of the way that it handles Windows Metafile (WMF) images."

These are the first fixes issued for the still-in-development Windows Vista.

Patches have been posted on Microsoft's download center for both the initial Beta 1 and the follow-up December CTP (Community Technical Preview) versions of Vista.

Comment  | 
Print  | 
More Insights
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest, Nov. 10, 2014
Just 30% of respondents to our new survey say their companies are very or extremely effective at identifying critical data and analyzing it to make decisions, down from 42% in 2013. What gives?
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of November 16, 2014.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.