• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        "Critical" XPe bug fix available

        Jonathan Angel | Date: May 22, 2008 | Comments: 1



        • Print PDF
        • Filed Under: News

        Microsoft has released a "critical" security update for Windows XP Embedded. The fix stamps out bugs in the operating system's Jet database engine that, as the company has acknowledged, could let an attacker take control of a computer, and have already been exploited "in the wild."




        (Click here for a larger view of MSJet40.dll version information)

        The update provides a new version of MSJet40.dll, the Jet database engine that provides data access to applications such as Microsoft Access and Visual Basic. In security advisory 950627, first published on Mar. 21 and updated on May 13, Microsoft acknowledged that a weakness in the way Jet parses data could allow an attacker to take "complete control of an affected system," installing programs, creating accounts, and manipulating data.

        Attacks would occur via specially crafted files using Microsoft's Access' .MDB file format. "Specifically, customers with Microsoft Office could be at risk to e-mail or direct download attack scenarios. For example, an attacker could exploit the vulnerability by sending a Word file with a specially crafted .MDB file embedded in it to the user, then convincing the user to open the document or view the e-mail," the company said.

        In the March bulletin, Microsoft confirmed that such attacks had occurred in the wild. According to reports by our sister publication eWEEK.com, .MDB-based exploits of the Jet engine have taken place dating back as far as 2005. Reportedly, however, Microsoft did not provide updates to MSJet40.dll earlier because it believed that it had already blocked likely attack vectors. For example, Internet Explorer and Outlook were set to block .MDB files.

        Users of Windows Vista, Windows Server 2003 SP2, and Windows XP Service Pack 3 (SP3), are not vulnerable to the bug because they already include versions of MSJet40.dll equal to or higher than 4.0.9505.0. As of today, for example, XP SP3 comes with 4.0.9511.0 (as shown in the picture above).

        Windows XP Embedded (XPe) is, of course, inherently resistant to attacks, thanks to features such as the Enhanced Write Filter, which allows for a device to be returned to its default condition whenever it is restarted. Nonetheless, Microsoft recommends installing the update, which is designed for use with XPe's Desktop QFE Installer (DQI) Tool.

        To download the update, access Microsoft's Mobile & Embedded Communications Extranet (ECE), here (a user name and password are required). To see earlier coverage of the .JET database vulnerability on eWEEK.com, go here, here, and here.



        Related stories:
        • Microsoft patches Windows XP Embedded
        • Microsoft releases February 2008 updates for XP Embedded
        • Microsoft releases December 2007 updates for XP Embedded
        • Installing XP Embedded optional updates without rebuilding images
        • Optional updates released for Windows XP Embedded
        • Microsoft offers bimonthly Windows XPe updates
        • Caching device info in Windows XPe Target Designer
        • Making Windows XPe TCP/IP changes stick
        • Repairing DRM in Windows Media Player 11
        • Protecting Windows-based kiosks from user tampering
        • Screencast shows how to add resources to Target Designer
        • Windows XP Embedded team solicits inputs
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.