Windows XP
A new flaw in Windows XP could allow an attacker to execute code on a target system

Zero-day flaw hits Windows XP

Vulnerabilities in MFC42 and MFC71 could allow remote code execution

Written by Shaun Nichols in California

A new zero-day flaw has been reported in a system component of Microsoft's Windows XP.

Experts warned that, depending on the way in which the attack is conducted, the flaw could allow an attacker to execute code on a target system.

The vulnerability lies in two Windows components known as MFC42 and MFC71 which are part of the Windows API that is used by virtually all Windows applications to communicate with the operating system.

When the user opens a document that calls on the function, a condition could be created that leads to a crash and potentially allows an attacker to run malicious code on a user's system, according to Secunia.

There is currently no fix for the vulnerability, although Secunia said that the only applications known to access the components are HP's Photo & Imaging Gallery 1.1 and version 2.1 of the software/driver installer for HP's All-In-One series.

Secunia credited the discovery of the flaw to researcher Jonathan Sarba of the GoodFellas Security Research Team.

The group claimed to have notified Microsoft about the flaw on 21 June, but that it was not until earlier this month that the company acknowledged that it was working on a fix.

A Microsoft spokesperson would not directly comment on the report, but did tell vnunet.com that the company is looking into "new public claims of a possible vulnerability in Microsoft Windows".

Secunia classifies the vulnerability as 'moderately critical', the third of its five alert levels.

Administrators looking to minimise risk from the flaw should block user access to applications that use the vulnerable MFC components.

See also:

reader comments

related articles

OpenOffice hit by 'highly critical' flaw

Problems dealing with Tiff images could allow remote access 18 Sep 2007

 

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities 12 Sep 2007

'Greynets' waiting to snare enterprises

Consumer messaging apps leaving companies at risk 11 Sep 2007

Security patching causes IT headache

Absent machines and corporate visitors could pose threat 11 Sep 2007

Security flaw hits MSN Messenger

Vulnerability puts users at risk of arbitrary code execution 29 Aug 2007

QuickTime zero-day spotted

Flaw also affects latest iTunes 19 Sep 2008

Microsoft plans emergency IE7 patch

Internet Explorer update could be the Grinch for admin holiday plans 17 Dec 2008

Security world makes short work of Chrome

Google browser open to 'carpet bomb' attack 04 Sep 2008

latest news

Novell to shuffle EMEA executive pack

Linux vendor shifts partner programme responsibilities to marketing organisation 09 Jan 2009

Ballmer highlights aims for New Year

Ballmer announces Windows 7 beta and future alliances designed to improve information sharing 08 Jan 2009

Active Storage completes UK Jigsaw

Jigsaw unveiled as Raid vendor's first non-US Platinum partner as it launches in Europe 08 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation