Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


December 16, 2004

Critical Update for Windows Firewall Flies Under the Radar

RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
On December 14 Microsoft issued five new security bulletins. But as it turns out Microsoft issued another critical security update one day prior to their regular monthly bulletin release. A critical update for Windows Firewall that changes its behavior was released on December 13 and not announced to the public via the company's security bulletin service however the patch is listed at the company's Download Center.

According to Gary Schare, Product Director at Microsoft, the company only issues security bulletins for "code vulnerabilities" but didn't explain what constitutes such a vulnerability. It seems safe to assume that changes to software behavior due to previously unknown conditions--even if such changes are critical to enhanced security--will not be included in Microsoft security bulletins. Some people have expressed that they'd like to see such updates included in Microsoft's monthly security bulletins.

Those who do not keep the automatic update service constantly enabled or do not regularly visit the Download Center could remain unaware of the critical problem since the update isn't currently listed at any of the company's security-related Web sites.

Schare said that the company did post an article about the problem, "Making File and Printer Sharing Safer in Windows XP Service Pack 2," on their Windows XP home page back in September. The article offers tips on how to avoid exposing file and printer shares while using the Windows Firewall and the article will be updated to include information about the release of the update.

According to the related knowledge base article 886185 Windows Firewall users might find that after connecting to the Internet using a dialup connection that their machines are open to access by anyone, which explains the critical rating given to the patch by Microsoft.

When the firewall option "My network (subnet) only" is used Windows Firewall does not properly interpret local subnets. In some cases the firewall interprets the entire Internet as the local subnet. The error could lead to the exposure of all available system services including printer and file shares to anybody on the Internet. The KB article explains that this problem is due to the way some dialing software packages configure routing tables. Obviously anybody who relies on Windows Firewall for protection should download and install the update immediately.

In addition to the five new security bulletins issued on December 14 Microsoft also updated bulletin MS04-028, which relates to the JPEG Processing (GDI+) vulnerability, to inform customers that standalone updates are available for Microsoft .NET Framework 1.0 with SP2 and .NET Framework 1.1. Security updates are also available Visual FoxPro 8.0 including the runtime module. The company also released Windows Messenger 5.1 to fix the security issue related to bulletin MS04-28, as well as updated version of their Enterprise Update Scanning Tool .

On a more seasonal note, Microsoft released a new Christmas Theme for Windows XP users which includes "new wallpaper, animated cursors, new icons, new sounds and a 3D screensaver." Ho ho ho!

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Top 10 Email Security Challenges and Solutions

Implementing VoIP for Your Enterprise

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing