Releaselog

Microsoft fixes critical Windows flaw

Microsoft has released its November security updates, fixing a critical Windows bug that has been exploited by online criminals. Microsoft released just two security updates this month, but security experts say that IT staff will want to install both of them as quickly as possible. The MS07-061 update is particularly critical because the flaw it repairs has been seen in Web-based attack code, said Amol Sarwate, manager of Qualys’s vulnerability research lab. “This was a zero day [flaw] that was being used in the wild by hackers,” he said.

The flaw has to do with the way Windows passes data between applications, using a technology called the URI (Uniform Resource Identifier) protocol handler. This is the part of Windows that allows users to launch applications — an e-mail or instant messaging client, for example — by clicking on a Web link. Because Windows does not perform all of the security checks necessary, hackers found ways to sneak unauthorized commands into these Web links and the flaw could be exploited to install unauthorized software on a victim’s PC. Microsoft’s patch for this problem is rated critical for Windows XP and Windows Server 2003 users, but the bug does not affect Windows 2000 or Vista, Microsoft said. Better update than be angry when someone hacks your computer…

Source: PC World 

Comments (21)

Feel free to post your Microsoft fixes critical Windows flaw torrent, subtitles, samples, free download, quality, NFO, rapidshare, megaupload, filefactory, netload, crack, serial, requirements or whatever-related comments here. Don't be rude (permban), use only English, don't go offtopic and read FAQ before asking a question. Owners of this website aren't responsible for content of comments.
  1. me
    November 15th, 2007 | 11:22

    windows hacked….never!

  2. me
    November 15th, 2007 | 11:23

    :)

  3. jared
    November 15th, 2007 | 11:37

    :O good thing i’m running win95! i’m not affected

  4. You
    November 15th, 2007 | 11:39

    I felt the hack. Had to reboot yesterday. Comp restarted as soon as i logged on :/ Im cured now

  5. jared
    November 15th, 2007 | 11:50

    great to have ya back #4

  6. Anon
    November 15th, 2007 | 11:56

    haha good thing im still running dos im never hacked!!!! and never affected and plagued by these updates!

  7. Eddie
    November 15th, 2007 | 12:36

    Thank you to all the security experts, hackers and Microsoft for identifying, testing and patching these vulnerabilities for free, making my operating system ever so safe.

  8. blobsters
    November 15th, 2007 | 12:49

    good thing i wasn’t hacked…i’d have to open a can of whoop-ass!

  9. Silicate
    November 15th, 2007 | 13:01

    At times, I do wonder if all these critical updates which are not needed for the newest OS really exist?

  10. Bobek
    November 15th, 2007 | 13:07

    And how long yook them to fix this issue? I bet at least 2-3 months. again.

  11. mr deadman
    November 15th, 2007 | 13:14

    oh yea… i got a virtual postcard that was off some random spammer that linked to a webpage with the code mentioned, i used ff and the script blocker plugin to get the code.. ive been playing with it ever since, its quite usefull lol

  12. Phishybongwaters
    November 15th, 2007 | 15:51

    Are you telling me I have to make ANOTHER build of the customXP disk I just burnt? You sons of satan!

    The only thing worse than microsoft’s buggy software is stupid spammers like #12 mark

    An idea … for articles like this one, relating to MS fixes and such, it might be good to add a link to, or mention of, the various means of getting MS updates without using windowsupdate. There are various sites and apps that can do this for you and some of the users here might appreciate that. No, I’m not talking about cracked WGA or anything like that, merely the sites that supply all the fixes and updates on their own servers, so you can completely circumvent MS.

  13. tramp
    November 15th, 2007 | 16:38

    It was a zero-day bug… for XP and 03! How have they not noticed this sooner!?

  14. darkmanmd
    November 15th, 2007 | 16:53

    So, knowing that you are a helpful guy/girl..who really knows.. ;-) what might be the name of the programs or sites that let you circumvent MS tramp?

  15. Sum of 3 + 9
    November 15th, 2007 | 17:23
  16. hikaricore
    November 15th, 2007 | 19:50

    IMHO there is still a critical flaw.
    No one has executed Bill, Steve, and the developers yet.

    Maybe Santa will bomb Redmond for Christmas?

  17. Bless`Em`With`A`Shotgun`Blast
    November 15th, 2007 | 19:53

    You know when windows tuesday’s monthly fixes come around I am usually looking at 5 or 6 security fixes. What do winxp users get instead? 1 damn patch for this problem with drm bug that shipped with windows 6 years ago. WOW!! Way to help out the users.. out of all the problems with windows they give us 1 patch for some useless drm problem.

    @15 - A very useful site, better then windows update and faster also.

    I can’t use windows expolorer for some reason after I nlited my OS. I will have to figure out what I did wrong, but it has to do with the slipstreaming of the latest 7.0 release that removes the wga.

  18. Silence
    November 15th, 2007 | 20:01

    This POC demonstrates this vulnerability:
    http:%xx../../../../../../../../../../../windows/system32/calc.exe”.bat
    mailto:test% ../../../../windows/system32/calc.exe”.cmd

  19. goatman
    November 16th, 2007 | 01:03

    so this is the update that waited till i was sleeping and in the middle of downloading a 4 gig file!!! which off course with all windows updates it forces your computer to restart!!!! so when i woke up i was greeted with a restarted computer and an incomplete download…

    Microsoft need to get rid of the forced restart with its updates!

  20. koopsta
    November 16th, 2007 | 02:06

    @19

    LOL DUDE turn off automatic updates, change it to notify only or such

  21. taint
    November 16th, 2007 | 15:40

    after getting the security update now my utorrent doesnt work properly. wtf

Your Ad Here

Leave a reply

Hot info about new scene releases!