• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Microsoft plugs XPe security holes

        Jonathan Angel | Date: Nov 4, 2008 | Comments: 1



        • Print PDF
        • Filed Under: News

        Microsoft has released its monthly batch of security updates for Windows XP Embedded (XPe). Announced on Microsoft's Windows Embedded Standard blog, and available now on its Mobile and Embedded Communications Extranet (ECE), the October batch boasts ten different fixes, including four rated "critical."




        The "critical" fixes are said to repair vulnerabilities that could potentially allow an attacker to take complete control of a computer. Via remote code execution, an attacker could install programs, view, change, or delete data, and create new accounts with full user rights, according to Microsoft.

        The four "critical" patches are said to include:
        • KB 938464, which resolves vulnerabilities in the Windows GDI (graphics device interface) that could allow remote code execution if a user views a maliciously crafted image file.

        • KB 956390, which updates six different vulnerabilities in the Internet Explorer web browser. Without the updates, specially crafted web pages could be used to gain information or execute code remotely, says Microsoft.

        • KB 958644, which resolves a "wormable" vulnerability in Windows' Server service. Without the fix, the operating system could allow remote code execution if a system receives a specially crafted RPC (remote procedure call) request.

        • KB 954154, resolving a vulnerability in Windows Media Player that could allow remote code execution when a specially crafted audio file is streamed from a Windows Media Server. This fix applies only to Update Rollup 1.0, says Microsoft.
        Five additional "important" patches include:
        • KB 954211, which fixes three vulnerabilities in the Windows kernel that could let an attacker take complete control of an affected system. The vulnerabilities could not be exploited remotely or by anonymous users, the company adds.

        • KB 953155, which resolves a vulnerability in Windows' IPP (internet printing protocol) service. By changing the way memory is allocated in the service, the fix prevents potential remote code execution, says Microsoft.

        • KB 957095, which resolves a vulnerability in the Windows SMB (server message block) protocol. The fix prevents potential remote code execution on servers that are sharing files or folders, the company says.

        • KB 956841, which resolves a vulnerability in the way Windows handles memory allocation and VADs (virtual address descriptors). Without the fix, an attacker could gain elevation of privilege by running a specially crafted program, according to Microsoft.

        • KB 956803, which resolves a vulnerability in the AFD (ancillary function driver). The fix ensures proper validation of input passed from user mode to the Windows OS kernel, avoiding local execution of code that would let an attacker take complete control of system, says Microsoft.
        Finally, KB 956391 is billed as a "Cumulative Security Update of ActiveX Kill Bits." The update deactivates versions of ActiveX controls that have been deemed flawed by their third-party developers, including versions of Microgaming's download helper, Husdawg's "System Requirements Lab," and PhotoStockPlus's uploader tool, according to Microsoft.

        Further information

        With the exception of KB 954154, noted above, the fixes are all for Windows XP Embedded with SP2, Feature Pack 2007, and/or Update Rollup 1.0. For more information on any of them, click on the links provided above, which lead to corresponding entries in Microsoft's online knowledge base.

        To obtain the October 2008 batch of security updates, access Microsoft's Mobile and Embedded Communications Extranet (ECE), here (registration required).



        Related stories:
        • Microsoft releases "optional" XPe patches
        • Microsoft releases "critical" XPe patches
        • August brings four critical XPe patches
        • Microsoft re-patches XPe
        • Microsoft releases "optional" XPe updates
        • "Critical" XPe bug fix available
        • Microsoft patches Windows XP Embedded
        • Microsoft releases February 2008 updates for XP Embedded
        • Microsoft releases December 2007 updates for XP Embedded
        • Installing XP Embedded optional updates without rebuilding images
        • Optional updates released for Windows XP Embedded
        • Microsoft offers bimonthly Windows XPe updates
        • Caching device info in Windows XPe Target Designer
        • Making Windows XPe TCP/IP changes stick
        • Repairing DRM in Windows Media Player 11
        • Protecting Windows-based kiosks from user tampering
        • Screencast shows how to add resources to Target Designer
        • Windows XP Embedded team solicits inputs
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.