Worm hole found in Windows 2000
A serious flaw has been discovered in a core component of Windows 2000, with no possible workaround until it is fixed, a security company has said.
The vulnerability in Microsoft's operating system could enable remote intruders to enter a PC via its Internet Protocol address, Marc Maiffret, chief hacking officer at eEye Digital Security, said on Wednesday. As no action on the part of the computer user is required, the flaw could easily be exploited to create a worm attack, he noted.
What may be particularly problematic with this unpatched security hole is that a workaround is unlikely, he said.
"You can't turn this component off," Maiffret said. "It's always on. You can't disable it. You can't uninstall."
eEye declined to give more details on the flaw or the Windows 2000 component in question. As part of company policy, it does not release technical details of the vulnerabilities it finds until the software's maker has released either a patch or an advisory.
A Microsoft representative said the software giant will issue a comment once it has had a chance to review the eEye advisory, which has yet to be posted on the security company's Web site.
The vulnerabilities affect Windows 2000, but Maiffret noted eEye is still conducting tests, and he anticipates other versions of Microsoft's OS will likely be affected.
For Microsoft, this marks the second eEye advisory it has received this week. On Monday, eEye notified the software giant it had found critical vulnerabilities in Internet Explorer.
The IE vulnerabilities could allow malicious attackers to launch a remote buffer overflow attack should users click on a malicious Web site link.
The flaw, which is rated a 'high' risk, affects IE, Windows XP and SP1, Windows 2003 and Windows 2000.
Microsoft confirmed it received the eEye advisory regarding IE through its standard vulnerability reporting system.
"We are investigating the report and will take appropriate action to help protect customers as part of our normal security response process," a Microsoft representative said. Microsoft issues a monthly bulletin of patches and also has a programme of security advisories with workarounds for unpatched reported flaws.
More about Software
- Obama in sex video shocker? Oh wait, it's just spam September 11, 2008
- No black holes from Large Hadron Collider, say scientists September 10, 2008
- Michael Moore to premiere film online September 05, 2008
- Images: Touring Google's Chrome browser September 05, 2008
- Extensions promised for Chrome September 04, 2008

- Video: Aptera and Fisker Karma electric cars
- Flip Video 'the future of journalism': UK chief blasts Sony, hints at HD
- Video: Taking a tour of the Chevy Volt hybrid
- Ford MyKey: Forcing kids to drive safely
- Photos: Hands-on with the Klipsch Palladium P-39F
- Panasonic DMP-BD35 and BD55: New ultra-sleek Blu-ray players

- Drunk emailing? Mail Goggles to the rescue
- Microsoft CEO Ballmer: Zune for Windows Mobile
- 'Oops I'm Late' app covers for you
- YouTube upgrade: Better uploader, 10x the file size
- Opinion: Why Yahoo Buzz will benefit Digg
- Living the D:Ream: Let's rename the Large Hadron Collider
- The 50 most significant moments of Internet history
- Google Android: Beyond the mobile phone
- Google to show UK religious group's anti-abortion ads
- Norton AntiVirus 2009: First Norton not to suck?
- Seismometer and Movies: Our favourite new iPhone apps
- Best of the forums this week: Why Earth hasn't imploded
- Hands-on with iTunes 8 Genius: Einstein with dementia?
- Apple iTunes 8: Just add Genius
- New Zunes: Buying songs from radio and more


