• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Microsoft releases "critical" XPe patches

        Jonathan Angel | Date: Sep 22, 2008 | Comments: 1



        • Print PDF
        • Filed Under: News

        Microsoft has released its monthly batch of security updates for Windows XP Embedded (XPe). Announced on Microsoft's Windows Embedded Standard blog, and available now on the company's Mobile and Embedded Communications Extranet (ECE), the September updates include two fixes that address "critical" faults, the company says.




        The operating system fixes reportedly repair vulnerabilities that could potentially allow an attacker to take complete control of a computer. Via remote code execution, an attacker could install programs, view, change, or delete data, and create new accounts with full user rights, according to Microsoft.

        The first patch is billed as KB 938464, "Vulnerabilities in GDI+ could allow remote code execution." Responding to "several privately reported vulnerabilities," Microsoft has modified XPe's GDI+ (Graphics Device Interface plus) dynamic link library, which provides two-dimensional vector graphics, imaging, and typography. Without the supplied fixes to GDIPLUS.DLL, maliciously created images could create memory buffer overflows that enable remote code execution, the company warns.

        The second patch is billed as KB 954154, "Vulnerability in Windows Media could allow remote code execution." Again responding to "a privately reported vulnerability" rather than an actual attack, Microsoft says it has modified the WMPEFFECTS.DLL supplied with XPe as part of Windows Media Player 11. Without the fix, a specially crafted audio file could allow remote code execution when streamed from a Windows Media server using Windows Media Player 11, the company says.

        Further information

        Windows XP Embedded (XPe) is inherently more resistant to attacks than its standard desktop cousin, thanks to features such as the Enhanced Write Filter, which allows for a device to be returned to its default condition whenever it is restarted. Nonetheless, Microsoft rates the above vulnerabilities as "critical," and recommends that customers apply the updates immediately.

        For more information on either vulnerability, click on the links provided above, which lead to corresponding entries in Microsoft's online knowledge base. To download Microsoft's September 2008 security patches for XPe, access the ECE, here (a user ID and password will be required).



        Related stories:
        • Microsoft releases "optional" XPe patches
        • August brings four critical XPe patches
        • "Critical" XPe security fixes now available
        • "Critical" XPe bug fix available
        • Microsoft patches Windows XP Embedded
        • Microsoft releases February 2008 updates for XP Embedded
        • Microsoft releases December 2007 updates for XP Embedded
        • Installing XP Embedded optional updates without rebuilding images
        • Optional updates released for Windows XP Embedded
        • Microsoft offers bimonthly Windows XPe updates
        • Caching device info in Windows XPe Target Designer
        • Making Windows XPe TCP/IP changes stick
        • Repairing DRM in Windows Media Player 11
        • Protecting Windows-based kiosks from user tampering
        • Screencast shows how to add resources to Target Designer
        • Windows XP Embedded team solicits inputs
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.