The Channel logo


By | John Leyden 12th November 2008 12:31

MS patch Tuesday includes fix for seven-year old itch

Better late than never

Microsoft's light sprinkling of patches yesterday includes a fix that reportedly goes back seven years or more.

Tuesday brought updates from Microsoft for a critical flaw in XML core services, which might allow memory corruption and code execution, and a flaw in SMB (Server Message Block). SMB is code which allows file shares over a network, and Microsoft labels the flaw as "important" but security watchers at the Internet Storm Centre give it a more severe "critical" prognosis.

Microsoft acknowledges that tools such as Metasploit have been able to carry out an attack based on the SMB vulnerability without saying how long the flaw has been around.

According to Metasploit, the flaw was first demonstrated by Sir Dystic at a hacking conference in 2001. Tests for the vulnerability have been available since July 2007, it adds.

Flaws in the NTLM Authentication flaw that's the subject of the patch were demonstrated at Defcon as far back as 2000, by Christian Rioux of Veracode (AKA dildog), according to BugTraq postings.

It's unclear why it took so long for Microsoft to fix the flaw.

A fuller explanation of both vulnerabilities that are the topic of this month's patch batch can be found in Microsoft's summary here or a more readable overview from the Internet Storm Centre here. ®

comment icon Read 9 comments on this article alert Send corrections


Frank Jennings

What do you do? Use manual typwriters or live in a Scottish croft? Our man advises
A rusty petrol pump at an abandoned gas station. Pic by Silvia B. Jakiello via shutterstock

Trevor Pott

Among other things, Active Directory needs an overhaul
Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella


League of gentlemen poster - Tubbs and Edward at the local shop. Copyright BBC
One reselling man tells his tale of woe