Windows XP
A new flaw in Windows XP could allow an attacker to execute code on a target system

Zero-day flaw hits Windows XP

Vulnerabilities in MFC42 and MFC71 could allow remote code execution

Written by Shaun Nichols in California

A new zero-day flaw has been reported in a system component of Microsoft's Windows XP.

Experts warned that, depending on the way in which the attack is conducted, the flaw could allow an attacker to execute code on a target system.

Advertisement

The vulnerability lies in two Windows components known as MFC42 and MFC71 which are part of the Windows API that is used by virtually all Windows applications to communicate with the operating system.

When the user opens a document that calls on the function, a condition could be created that leads to a crash and potentially allows an attacker to run malicious code on a user's system, according to Secunia.

There is currently no fix for the vulnerability, although Secunia said that the only applications known to access the components are HP's Photo & Imaging Gallery 1.1 and version 2.1 of the software/driver installer for HP's All-In-One series.

Secunia credited the discovery of the flaw to researcher Jonathan Sarba of the GoodFellas Security Research Team.

The group claimed to have notified Microsoft about the flaw on 21 June, but that it was not until earlier this month that the company acknowledged that it was working on a fix.

A Microsoft spokesperson would not directly comment on the report, but did tell vnunet.com that the company is looking into "new public claims of a possible vulnerability in Microsoft Windows".

Secunia classifies the vulnerability as 'moderately critical', the third of its five alert levels.

Administrators looking to minimise risk from the flaw should block user access to applications that use the vulnerable MFC components.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Podcast image

28 Nov 2008

12.57 MBComputing podcast - Standard Life's offshoring plans; and the prospects for government IT More...

Shaun Nichols and Iain Thomson

28 Nov 2008

7.11 MBPodcast Special: Views from the Valley More...

Shaun Nichols and Iain Thomson

21 Nov 2008

9.11 MBPodcast Special: Views from the Valley More...

Poll

Microsoft

Unified Communications: Collaboration

Unified Communications: Collaboration

What is the main advantage of using collaboration technologies?

Previous poll results

Spotlight

Sony Ericsson Xperia X1

Review: Sony Ericsson Xperia X1

The first Xperia smartphone bodes well for the future   More...

VMware

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can...  More...

Apple iPhone 3G

Linux lands on the iPhone

Developers put kernel on Apple handset   More...

Data theft

IT staff desperate to keep their jobs

Most would work longer hours for less pay   More...

Primary Navigation