Microsoft Reissues Critical Security Fix For Windows XP
The original patch worked on Windows Vista, but failed to accomplish its task in Windows XP SP2 and SP3, the Microsoft Security Response Center said.
Microsoft has reissued a critical patch for the Bluetooth stack in Windows XP, saying the original fix did not correct a vulnerability that a hacker could exploit to take control of a PC.
The original patch worked on Windows Vista, but failed to accomplish its task in Windows XP SP2 and SP3, Christopher Budd, a member of the Microsoft Security Response Center, said in the group's blog.
More Security Insights
Webcasts
- Securing the Cloud: Extend the Benefits of Traditional IT Environments to Cloud
- Perform Better in a Hybrid Cloud World
White Papers
- Aberdeen Report: Endpoint Security and Endpoint Management in the Era of Enterprise Mobility and BYOD: Still Better Together
- Gartner Client Management Tools Magic Quadrant
Reports
More >>After releasing the patch in Security Bulletin MS08-30, Microsoft engineers "learned that the security updates for Windows XP SP2 and SP3 might not have been fully protecting against the issues discussed in that bulletin," Budd said.
"Our investigation found that while the other security updates were providing protections for the issues discussed in the bulletin, the Windows XP SP2 and SP3 updates were not," he said.
The latest patch would be distributed through the same channels as the original fix, including Microsoft's Automatic Update tool.
A preliminary investigation of the original failing has found that it may be related to "two separate human issues," Budd said, offering no other details. "When we’re done with our investigation, we’ll take steps to better prevent it in the future."
The vulnerability within the Bluetooth stack, which handles communications over the wireless specification, would enable an attacker to install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft labeled the flaw "critical."
Microsoft released the original fix June 10 in a package of seven security patches addressing 10 vulnerabilities. Three of the bulletins were rated "critical," three "important," and one "moderate."
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- Why Bad Guys Write Malware– And What You Can Do About It
- Securing the Cloud: Extend the Benefits of Traditional IT Environments to Cloud
- Protecting End Users Against Emerging Threats
- Perform Better in a Hybrid Cloud World
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Meeting the Challenges of Endpoint Security
- Aberdeen Report: Endpoint Security and Endpoint Management in the Era of Enterprise Mobility and BYOD: Still Better Together
- Gartner Client Management Tools Magic Quadrant
- Establishing a Data-Centric Approach to Encryption
- Desktop Virtualization: Improve Data Protection, Security and Efficiency
Featured Resource
Download this paper to learn how Dell computers running Microsoft Windows 7 can help you make your operations more secure and meet compliance requirements.
Learn More












