Click here to learn
about this Sponsor:
Home  |  News  |  Articles  |  Polls  |  Forum  |  Directory

Keywords: Match:
"Critical" XPe security fixes now available
Jun. 19, 2008

Microsoft has released four critical security fixes for the Jet database engine, Bluetooth stack, web browser, and media player in Windows XP Embedded (XPe). Along with two others fixes, rated "moderate" and "important," the patches are available now on the Mobile & Embedded Communications Extranet (ECE), Microsoft says.

In a posting on its Windows Embedded Standard (WES) blog, the company listed the updates as follows:
  • KB 950749 -- Vulnerability in Microsoft Jet database engine could allow remote code execution
  • KB 951376 -- Vulnerability in Bluetooth stack could allow remote code execution
  • KB 950759 -- Cumulative security update for Internet Explorer
  • KB 951698 -- Vulnerabilities in DirectX could allow remote code execution
  • KB 950760 -- Cumulative security update of ActiveX kill bits
  • KB 950762 -- Vulnerabilities in pragmatic general multicast (PGM) could allow denial of service
Like a vulnerability fixed by Microsoft last month, KB 950749 apparently involves the Jet database engine, used by XPe to provides data access to applications such as Microsoft Access and Visual Basic. Once again, the vulnerability is rated "critical," since it could allow an attacker to take complete control of a computer. The attack vector would be a Word document containing a specially crafted file using Microsoft's Access .MDB file format, according to the company.

KB 951376, also "critical," involves a vulnerability in XPe's Bluetooth stack. Again, it could allow remote code execution, which permits an attacker to install programs, view, change, or delete data, and create new accounts with full user rights. The fix modifies the way that the Bluetooth stack responds when bombarded with a large number of service description requests, says Microsoft.

A third "critical" vulnerability, denoted as KB 950759, involves the possibility of remote code execution if Internet Explorer is used to view a maliciously crafted web page. The fix modifies the way that the web browser validates data and handles calls to HTML objects, according to Microsoft.

A fourth "critical" vulnerability, KB 951698, involves potential remote code execution via DirectX, in cases where a user opens a specially crafted media file. The fix modifies the way that DirectX handles MJPEG (motion JPEG) and SAMI (synchronized accessible media interchange) files, Microsoft notes.

KB 950760, rated "moderate," concerns the possibility of remote code execution via malicious web pages, in cases where a user has XPe's speech recognition feature enabled. The fix sets "kill bits" in the Windows registry so that related ActiveX controls cannot run within Internet Explorer. It also sets a kill bit disabling a specific version of the third-party BackWeb client, Microsoft says.

Finally, KB 950762, rated "important," concerns vulnerabilities in the PGM (pragmatic general multicast) protocol that could allow a denial of service if malformed PGM packets are received. Although this vulnerability does not allow an attacker to execute code, it could cause a user’s system to become non-responsive and require a restart, according to Microsoft. The fix modifies the way PGM parses malformed packets, the company adds.

XPe is more resistant to attacks than other versions of Windows, thanks to features such as the Enhanced Write Filter, which allows for a device to be returned to its default condition whenever it is restarted. Nonetheless, Microsoft strongly recommends installing the fixes, which are cumulative and include updates for XPe's Desktop QFE Installer (DQI) Tool and Component Database.

For further information on any of the vulnerabilities, click on the links in the list above. To download the updates, access Microsoft's Mobile & Embedded Communications Extranet (ECE), here (a user name and password are required).

The fixes are for XPe with SP2, Feature Pack 2007, and/or Update Rollup 1.0.



Related stories:




(Click here for further information)


Windows XP for Embedded Applications
This white paper describes the benefits of using Windows XP when developing embedded applications.

A Manager's Guide to Selecting a Mobile Device Operating System
This white paper offers a comparative review of Microsoft Windows CE and Windows Mobile.

Visual Basic 6.0 to .NET Migration
This paper focuses on the methodology and techniques which Infosys (Microsoft Technology Center) has developed for migrating VB 6.0 Applications to .NET. Our approach ensures a smooth, cost effective, and efficient migration.

Mobile Device Security: Securing the Handheld, Securing the Enterprise
This whitepaper identifies security threats to corporate data on mobile devices and details how mobile devices can become a "backdoor" to the enterprise.

Mobile Device Security: The Eight Areas of Risk
It's common knowledge that adding mobile devices to your network increases security risks. There are multiple facets to mobile security, all of which should be paid close attention to. This E-Guide presents a more in depth look into the eight key areas of securing wireless devices.

Quality Assurance and .NET
This paper discusses best practices for functional, regression and load testing of .NET applications.

SCADA Security in Integrated Networks
As businesses leverage their SCADA systems by integrating them into the business networks, they must also assure the security of the SCADA system.

The Advantages of Small Form Factor HMI
HMIs have mutated and changed with new requirements, and they have become more flexible and capable. And while they've been doing that, they've become smaller and more useful.

9 Critical Requirements for Web Application Security
Learn why your Web applications expose dangerous security breaches and what’s required to effectively protect your Web applications and the sensitive information behind them.

 


Got a HOT tip?   please tell us!
Free weekly newsletter
Enter your email...
Click here for a profile of each sponsor:
PLATINUM SPONSORS
(Become a sponsor)

ADVERTISEMENT
(Advertise here)


Updated! The latest Windows-powered...

mobile phones!

other cool
gadgets

HOT TOPICS
Microsoft targets PNDs with new embedded OS
Microsoft tips .NET MF 3.0 highlights
Microsoft previews Windows Embedded Standard
Microsoft offers free Windows CE 6.0 textbook
Microsoft renames embedded operating systems
Microsoft unveils Windows Mobile 6.1
New Atom models target low-cost PCs
REFERENCE GUIDES
Windows Device Showcase
Intro to Windows Embedded
Intro to Shared Source
Real-time Windows Embedded
Windows Embedded books
Join our Windows Embedded discussion forums:
Windows XP Embedded
Windows CE
Windows Mobile


Windows Embedded developer newsgroups
Windows CE
XP Embedded
PocketPC
Smartphone

Microsoft's Windows Embedded resources
Embedded dev center
Mobile dev center
Windows CE tutorials
XP Embedded tutorials
Windows Embedded seminars
Windows Embedded application categories
3rd-party partners


BREAKING NEWS

• Qseven module sports Atom
• Windows Mobile phone has evil Android twin
• Japanese smartphone does widgets
• Microsoft baking a phone?
• Tutorial covers SQL database for Windows Mobile
• Smartphone vendor announces layoffs
• New Microsoft smartphone OS rumored
• Wyse beefs up thin clients
• Webcast explains Windows Mobile networking
• Omnia tipped for Verizon debut
• STD bus SBC runs Windows XP Embedded
• Tactical computer muscles up
• Carriers holding browser upgrade hostage?
• Software syncs Macs and Windows Mobile
• Windows handheld collects in-flight payments


MOST POPULAR (last 90 days)
• "Netbook" uses Intel's Atom N270
• Windows CE takes on Linux in low-end netbooks
• Windows Mobile 6.1 phone has GPS
• T-Mobile's Touch Diamond clone does HSUPA
• iPhone-like Windows Mobile device has 16GB of storage
• HTC phone has slide-out keyboard and TV output
• Windows Mobile trouncing the iPhone?
• HTC releases Touch Diamond ROM upgrade
• Sprint upgrades HTC Touch, Mogul
• Intel's Atom powers mini-ITX board
MOST POPULAR (Classics from the vault)
Windows XP Embedded USB boot
Troubleshooting Windows XPe's blue screen "Stop 0x0000007B" error
Asus reveals $190 mini notebook
Windows Mobile 6 SDKs available for download
Windows Mobile VPN client plays with Cisco
HTC adds GPS to Windows Mobile Touch line
Microsoft unveils Windows Mobile 6.1
Guide to HTC's Windows Mobile smartphone platforms
Customizing Windows XP Embedded thin clients
Visual Studio 2008 adds mobile application features

Also visit our sister sites:


Sign up for WindowsForDevices.com's...

news feed

Home  |  News  |  Articles  |  Polls  |  Forum  |  Directory  |  About  |  Contact
 

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
Tech RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video | VARs | Channel News

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | Enterprise Network Security | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | Security IT Hub | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | igrep

Use of this site is governed by our Terms of Service and Privacy Policy. Except where otherwise specified, the contents of this site are copyright © 1999-2008 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise is prohibited. Windows is a trademark or registered trademark of Microsoft Corporation in the United States and/or other countries and is used by WindowsForDevices under license from owner. All other marks are the property of their respective owners. WindowsForDevices is an independent publication not affiliated with Microsoft Corporation.