- IE 8 hits Beta 2, privacy features added
- 10 Firefox add-ons for better browsing
- Cisco buys PostPath
- 595 immigrants arrested at electronics plant
- Locked iPhones can be unlocked without password
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Microsoft has reissued a critical Windows security patch, saying that the fix didn't initially work on the most recent versions of Windows XP.
Microsoft learned of the problem after releasing its security updates last Tuesday, said Christopher Budd, a Microsoft spokesman, writing in a Thursday blog posting. "Our investigation found that while the other security updates were providing protections for the issues discussed in the bulletin, the Windows XP SP2 and SP3 updates were not," he wrote.
The patch, described in the MS08-030 security bulletin, fixes a flaw in the way Windows uses the Bluetooth networking protocol, used to connect peripheral devices like headsets to the PC. An attacker who got close enough to the Windows system to make a Bluetooth connection could theoretically send malicious packets to the PC and take complete control of a victim's computer.
Security experts say that because Bluetooth devices need to be within a few yards of a computer to connect, the flaw wouldn't be used in a widespread attack, but it is considered a serious bug.
Budd didn't offer much of an explanation for the error, saying that it looks like "two separate human issues" were to blame. "We’re beginning an investigation into how this happened."
Microsoft is now pushing out a new, working version of the patch via its automatic update mechanisms.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comments (1)
Widespread attack possibleBy Anonymous on June 21, 2008, 1:40 pmI regularly test Bluetooth exploits with my class 1 USB dongle at over 80m. It cost me about $60 from a website in the UK.
Reply | Read entire comment
View all comments