• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Microsoft patches Windows XP Embedded

        Jonathan Angel | Date: Apr 18, 2008 | Comments: 1



        • Print PDF
        • Filed Under: News

        Microsoft has released its April 2008 batch of updates to Windows XP Embedded (XPe). Available now on the Mobile & Embedded Communications Extranet (ECE), the seven security updates patch GDI (graphics device interface), ActiveX, Internet Explorer, and Windows kernel vulnerabilities, including remote code execution and permissions elevation exploits.




        According to a posting on the Embedded Windows team blog, the updates are cumulative, and include new releases of both the Desktop QFE Installer (DQI) Tool and the Component Database. Six of them apply to XPe Service Pack 2 with Feature Pack 2007 with Update Rollup 1.0 applied, while the seventh is for installations that do not have the update rollup.

        The first six security updates are detailed briefly in the posting, as follows:
        • KB 945553 -- Vulnerability in DNS client could allow spoofing
        • KB 948590 -- Vulnerabilities in GDI could allow remote code execution
        • KB 948881 -- Security update of ActiveX kill bits
        • KB 947864 -- Cumulative security update for Internet Explorer
        • KB 941693 -- Vulnerability in Windows kernel could allow elevation of privilege
        The above security updates fix issues that have also been found in other Microsoft operating systems, such as Windows XP or Server 2003. Therefore, detailed articles on each can be found in Microsoft's Knowledgebase by clicking on the links provided above.

        The seventh security update, specifically for systems without Update Rollup 1.0, is as follows:
        • KB 944338 -- Vulnerability in VBScript and JScript scripting engines could allow remote code execution
        Further information and availability

        As mentioned above, you can find out more about the security updates by clicking on the links leading to their corresponding Knowledgebase entries. You can also read the Embedded Windows team's posting announcing the security updates, here.

        An ECE user name and password is required to obtain the security updates, here.



        Related stories:
        • Microsoft releases February 2008 updates for XP Embedded
        • Microsoft releases December 2007 updates for XP Embedded
        • Installing XP Embedded optional updates without rebuilding images
        • Optional updates released for Windows XP Embedded
        • Microsoft offers bimonthly Windows XPe updates
        • Caching device info in Windows XPe Target Designer
        • Making Windows XPe TCP/IP changes stick
        • Repairing DRM in Windows Media Player 11
        • Protecting Windows-based kiosks from user tampering
        • Screencast shows how to add resources to Target Designer
        • Windows XP Embedded team solicits inputs
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • USB security device includes Windows Embedded Standard 7

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.