• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Microsoft releases "critical" patches for XPe devices

        Jonathan Angel | Date: Dec 5, 2008 | Comments: 1



        • Print PDF
        • Filed Under: News

        Microsoft has released its monthly batch of security updates for Windows XP Embedded (XPe). Announced on Microsoft's Windows Embedded Standard blog, and available now on its Mobile and Embedded Communications Extranet (ECE), the "November 2008 XP Embedded Security Updates" include two fixes for existing devices, both rated "critical."




        As in other months, the "critical" fixes are said to repair vulnerabilities that could potentially allow an attacker to take complete control of a computer. Via remote code execution, an attacker could install programs, view, change, or delete data, and create new accounts with full user rights, according to Microsoft.

        The first of the two patches is described, using Microsoft's online knowledge base numbering, as KB 938464, resolving "privately reported" vulnerabilities in the Windows GDI (graphics device interface). The vulnerability may have allowed remote code execution if a user viewed a maliciously crafted image file. But, by modifying GDIPLUS.DLL and other Windows files, the patch prevents this.

        The second of the two patches is described as KB 956390, which updates the Internet Explorer web browser to repair "five privately reported vulnerabilities and one publicly disclosed vulnerability." Once again, without the fix, remote code execution might be possible, says Microsoft.

        These patches might sound familiar to loyal readers, since they were already released as part of Microsoft's October 2008 XP Embedded Security Updates. The October version of the patches, however, merely entered them into XPe's component database, a part of the Target Designer toolkit that's accessed when new operating system images are being built. In contrast, the newly available November version provides the patches for XPe's Desktop QFE Installer (DQI). That apparently means the fixes can now be applied to existing XPe devices.

        Further information

        More information on the distinction between component database and DQI patches for XPe may be found on Microsoft's website, here. To obtain the November 2008 XP Embedded Security Updates from Microsoft's ECE, go here (prior registration required).



        Related stories:
        • Microsoft plugs XPe security holes
        • Microsoft releases "optional" XPe patches
        • Microsoft releases "critical" XPe patches
        • August brings four critical XPe patches
        • Microsoft re-patches XPe
        • Microsoft releases "optional" XPe updates
        • "Critical" XPe bug fix available
        • Microsoft patches Windows XP Embedded
        • Microsoft releases February 2008 updates for XP Embedded
        • Microsoft releases December 2007 updates for XP Embedded
        • Installing XP Embedded optional updates without rebuilding images
        • Optional updates released for Windows XP Embedded
        • Microsoft offers bimonthly Windows XPe updates
        • Caching device info in Windows XPe Target Designer
        • Making Windows XPe TCP/IP changes stick
        • Repairing DRM in Windows Media Player 11
        • Protecting Windows-based kiosks from user tampering
        • Screencast shows how to add resources to Target Designer
        • Windows XP Embedded team solicits inputs
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.