ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    New flaw found in XP and Windows 2000

Danish researchers have discovered a new vulnerability affecting two of Microsoft’s older operating systems.

By Jennifer Scott, 7 Jul 2010 at 13:24

Operating system flaw

A new flaw discovered in two of Microsoft’s operating systems is leaving machines vulnerable to hack attacks.

The “moderately critical” issue was discovered by Danish security research firm Secunia in Windows 2000 and XP, although the company indicated it could affect other versions too.

In a security advisory, Secunia said: “The vulnerability is caused due to a boundary error in the "UpdateFrameTitleForDocument()" function of the CFrameWnd class in mfc42.dll. This can be exploited to cause a stack-based buffer overflow by passing an overly long title string argument to the affected function.”

“Successful exploitation may allow execution of arbitrary code.”

Secunia has claimed the solution to the bug would be to “restrict access to applications allowing user-controlled input to be passed to the vulnerable function.”

Microsoft acknowledged the concerns via its Microsoft Security Response Twitter feed and said: “We are investigating reports of a vulnerability in mfc42.dll affecting Windows 2000 and XP. Will update when we have more information.”

Email to a friend

Print this page

< Previous   Operating Systems : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement