Microsoft releases security patch for Windows XP

By Ted Bridis

Associated Press

WASHINGTON – Microsoft’s newest version of Windows, billed as the most secure ever, contains several serious flaws that allow hackers to steal or destroy a victim’s data files across the Internet or implant rogue computer software. The company released a free fix today.

A Microsoft official acknowledged that the risk to consumers was unprecedented because the glitches allow hackers to seize control of all Windows XP operating system software without requiring a computer user to do anything except connect to the Internet.

Microsoft made available on its Web site a free fix for both home and professional editions of Windows XP and forcefully urged consumers to install it immediately.

The flaws, discovered five weeks ago by independent security researchers, threatened to undermine widespread adoption of Microsoft’s latest Windows software, which many hope will be an economic catalyst for the sagging technology industry.

The company sold more than 7 million copies of Windows XP in the two weeks after it hit stores Oct. 25.

The vulnerabilities were discovered by three young security researchers with eEye Digital Security Inc. of Aliso Viejo, Calif., led by Marc Maiffret, a 21-year-old former hacker. In recent months, Maiffret, who calls himself the firm’s “chief hacking officer,” has advised the FBI and the White House on Internet security questions and testified before Congress.

The Windows XP problems affect a little-used feature that eventually will allow consumers to control high-tech household appliances using their computers. Called “universal plug and play,” the feature is activated by design in every copy of Windows XP and can be added manually to Microsoft’s earlier Windows ME software, also used by millions of consumers worldwide.

“This is the first network-based, remote compromise that I’m aware of for Windows desktop systems,” said Scott Culp, manager of Microsoft’s security response center. “Every Windows XP user needs to immediately take action.” He called it a “very serious vulnerability.”

Microsoft said a new feature of Windows XP, known as “drizzle,” can automatically download the free fix, which takes several minutes to download, and prompt consumers to install it. Microsoft also is working with other software companies, such as leading antivirus and firewall vendors, to build protection into their products.

Maiffret and his researchers demonstrated the flaws for The Associated Press by hacking into a reporter’s laptop running Windows XP from 2,300 miles away and successfully instructing the computer to connect automatically several times to the Web site for the National Security Agency, the government’s super-secret spy agency.

Microsoft and Maiffret said there was no suggestion that anyone has used these flaws to break into any computers; Maiffret predicted that many hackers will be able to duplicate his firm’s research – and begin breaking into unprotected computers – “a couple months from now.”

Microsoft feared that hackers could exploit the flaws more quickly if eEye discloses too many details about its findings. Leading up to the public announcement, Culp said, those researchers behaved “exactly right” by quietly notifying Microsoft.

Riley Hassell, eEye’s self-described “network penetration specialist,” discovered methods for hackers to either disrupt a victim’s Windows XP computer, order it to attack other Internet users or instruct it to run commands – such as to delete or steal files or install rogue software.

“This is very serious,” said Maiffret. Hackers using these methods “could reformat your hard-drive, record your keystrokes,” he added.

Hackers could attack individual computers directly, though the flaws also allow hackers to transmit an attack to a single Internet address and strike all the nearby Windows XP computers within a corporation or neighborhood. Microsoft said companies and Internet providers can reduce the threat by properly configuring their Internet traffic-directing devices, called routers.

The flaws are particularly embarrassing to Microsoft because their discovery falls so close to Christmas and because of the company’s commercial emphasis on improved security in Windows XP. The company boasts as one of 10 reasons for technology experts to buy Windows XP the promise of a “safe, secure and private computing experience.”

“This is the most secure version of Windows we have ever released,” said Culp, adding that complex software “will always fall short of perfection.”

One of the problems disclosed today belongs to a category of software flaws known as “buffer overflows,” which can trick software into accepting dangerous commands. Another is the result of broader design problems with universal plug and play technology.

Just last week, Microsoft’s corporate security officer, Howard Schmidt, expressed frustration about continuing threats from overflows. “I’m still amazed that we allow these things to occur,” he said at a conference of technology executives. Schmidt is expected soon to resign from Microsoft to work for President Bush’s top computer security adviser.

On the Net: www.microsoft.com/security

Copyright ©2001 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Customers enter and exit the Costco on Dec. 2, 2022, in Lake Stevens. (Olivia Vanni / The Herald)
Costco stores could be impacted by looming truck driver strike threat

Truck drivers who deliver groceries and produce to Costco warehouses… Continue reading

Two Washington State ferries pass along the route between Mukilteo and Clinton as scuba divers swim near the shore Sunday, Oct. 22, 2023, in Mukilteo, Washington. (Ryan Berry / The Herald)
Ferry system increases ridership by a half million in 2024

Edmonds-Kingston route remains second-busiest route in the system.

Firefighters respond to a 911 call on July 16, 2024, in Mill Creek. Firefighters from South County Fire, Tulalip Bay Fire Department and Camano Island Fire and Rescue left Wednesday to help fight the LA fires. (Photo provided by South County Fire)
Help is on the way: Snohomish County firefighters en route to LA fires

The Los Angeles wildfires have caused at least 180,000 evacuations. The crews expect to arrive Friday.

x
Edmonds police shooting investigation includes possibility of gang violence

The 18-year-old victim remains in critical condition as of Friday morning.

The Everett Wastewater Treatment Plant along the Snohomish River. Thursday, June 16, 2022 in Everett. (Olivia Vanni / The Herald)
Everett council approves water, sewer rate increases

The 43% rise in combined water and sewer rates will pay for large infrastructure projects.

Robin Cain with 50 of her marathon medals hanging on a display board she made with her father on Thursday, Jan. 2, 2025 in Lake Stevens, Washington. (Olivia Vanni / The Herald)
Running a marathon is hard. She ran one in every state.

Robin Cain, of Lake Stevens, is one of only a few thousand people to ever achieve the feat.

People line up to grab food at the Everett Recovery Cafe on Wednesday, Dec. 4, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Coffee, meals and compassion are free at the Everett Recovery Cafe

The free, membership-based day center offers free coffee and meals and more importantly, camaraderie and recovery support.

Devani Padron, left, Daisy Ramos perform during dance class at Mari's Place Monday afternoon in Everett on July 13, 2016. (Kevin Clark / The Herald)
Mari’s Place helps children build confidence and design a better future

The Everett-based nonprofit offers free and low-cost classes in art, music, theater and dance for children ages 5 to 14.

The Everett Wastewater Treatment Plant along the Snohomish River on Thursday, June 16, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Everett water, sewer rates could jump 43% by 2028

The rate hikes would pay for improvements to the city’s sewer infrastructure.

The bond funded new track and field at Northshore Middle School on Thursday, Oct. 24, 2024 in Bothell, Washington. (Courtesy of Northshore School District)
Northshore School District bond improvements underway

The $425 million bond is funding new track and field complexes, playgrounds and phase one of two school replacements.

Riley Boyd, 6, left, and sisters Vivienne Boyd, 3, ride a sled together down a hill at Anderson Center Field on Thursday, Feb. 6, 2025 in Edmonds, Washington. (Olivia Vanni / The Herald)
UPDATED: Schools close across Snohomish County on Thursday

Snohomish County lowlands remain under cold weather and winter weather advisories.

Modern DNA tech comes through again for Everett police in 1989 murder case

Recent advances in forensic genealogy led to the suspect’s arrest in Clark County, Nevada.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.