• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Microsoft re-patches XPe

        Jonathan Angel | Date: Jul 17, 2008 | Comments: 1



        • Print PDF
        • Filed Under: News

        Microsoft has released its July 2008 batch of security updates for Windows XP Embedded. Two fixes, rated "critical" and "important" respectively, involve the operating system's Bluetooth stack and DNS functionality, and are available now on the Mobile & Embedded Communications Extranet (ECE), the company says.




        The fixes are for XPe with SP2, Feature Pack 2007, and/or Update Rollup 1.0. As always, Microsoft warns that XPe fixes are cumulative, and should be installed in the order they are released. The two new July 2008 Windows XP Embedded (XPe) security updates announced today arrive hot on the heels of the June 2008 "optional" updates belatedly released earlier this week.

        The first of the new July updates, denoted as KB 951376, addresses a vulnerability in XPe's Bluetooth stack that could allow remote code execution. Oddly, the Bluetooth vulnerability was supposedly already addressed in Microsoft's June batch of XPe security updates, which referenced the same Knowledge Base number. Microsoft did not state what changes might have been made to the newly offered patch. In any case, KB 951376 is rated as "critical," since potential remote code execution could allow an attacker to install programs, view, change, or delete data, and create new accounts with full user rights. The fix reportedly modifies the way that the Bluetooth stack responds when bombarded with a large number of service description requests (SDRs), according to Microsoft.

        The second update, denoted as KB 951748, addresses a threat rated as "moderate," involving vulnerabilities in the Windows DNS (domain name system) that could allow a remote attacker to redirect network traffic, according to Microsoft. The fix addresses the vulnerabilities by using strongly random DNS transaction IDs, using random sockets for UDP queries, and updating the logic used to manage the DNS cache, the company says.

        Further information

        For further information on any of the vulnerabilities, click on the Knowledge Base links cited above. To download the updates, access Microsoft's Mobile & Embedded Communications Extranet (ECE), here (a user name and password are required).



        Related stories:
        • Microsoft releases "optional" XPe updates
        • "Critical" XPe bug fix available
        • Microsoft patches Windows XP Embedded
        • Microsoft releases February 2008 updates for XP Embedded
        • Microsoft releases December 2007 updates for XP Embedded
        • Installing XP Embedded optional updates without rebuilding images
        • Optional updates released for Windows XP Embedded
        • Microsoft offers bimonthly Windows XPe updates
        • Caching device info in Windows XPe Target Designer
        • Making Windows XPe TCP/IP changes stick
        • Repairing DRM in Windows Media Player 11
        • Protecting Windows-based kiosks from user tampering
        • Screencast shows how to add resources to Target Designer
        • Windows XP Embedded team solicits inputs

      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.