Microsoft Reissues Critical Security Fix For Windows XP

The original patch worked on Windows Vista, but failed to accomplish its task in Windows XP SP2 and SP3, the Microsoft Security Response Center said.

Microsoft has reissued a critical patch for the Bluetooth stack in Windows XP, saying the original fix did not correct a vulnerability that a hacker could exploit to take control of a PC.

The original patch worked on Windows Vista, but failed to accomplish its task in Windows XP SP2 and SP3, Christopher Budd, a member of the Microsoft Security Response Center, said in the group's blog.


More Security Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

After releasing the patch in Security Bulletin MS08-30, Microsoft engineers "learned that the security updates for Windows XP SP2 and SP3 might not have been fully protecting against the issues discussed in that bulletin," Budd said.

"Our investigation found that while the other security updates were providing protections for the issues discussed in the bulletin, the Windows XP SP2 and SP3 updates were not," he said.

The latest patch would be distributed through the same channels as the original fix, including Microsoft's Automatic Update tool.

A preliminary investigation of the original failing has found that it may be related to "two separate human issues," Budd said, offering no other details. "When we’re done with our investigation, we’ll take steps to better prevent it in the future."

The vulnerability within the Bluetooth stack, which handles communications over the wireless specification, would enable an attacker to install programs; view, change, or delete data; or create new accounts with full user rights. Microsoft labeled the flaw "critical."

Microsoft released the original fix June 10 in a package of seven security patches addressing 10 vulnerabilities. Three of the bulletins were rated "critical," three "important," and one "moderate."


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links