• On The Insider: Britney's Bikini-Clad Top 10
April 11, 2007 11:04 AM PDT

Windows flaw adds to Microsoft's zero-day trouble

by Joris Evers
  • Font size
  • Print
  • Post a comment

In addition to a trio of zero-day bugs in Office, a yet-to-be-patched vulnerability has been reported in Windows.

Sample code that exploits a flaw in the way Windows handles help system files has been posted to the Internet.

"This is another heap-overflow flaw that might be exploited for code execution," McAfee reported on its Avert Labs blog late Tuesday.

Microsoft said it is aware of the issue and advises caution with ".hlp" files, which are as unsafe as ".exe," as both file types are executable, it said.

Word of the flaws comes just as Microsoft issued five security bulletins as part of its monthly patch cycle. The company is also still dealing with the aftermath of an emergency patch released last week. That patch fixed another Windows zero-day, one that is actively being exploited in attacks on Windows PCs.

None of the newly reported bugs are being used in cyberattacks, according to Microsoft. Not yet, at least.

You can read more on the Patch Tuesday zero-day parade in a story I wrote on Tuesday that has been recently updated.

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
advertisement

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right