Advertisement
Promo

Security threats Toolkit

Story: Microsoft starts frantic bug hunt

  • Previous comment

Posted by: Anonymous (Tuesday 10 January 2006, 2:04 PM)

  • Reply

The common (and certainly correct) assumption is that, as soon as a vulnerability is discovered in a MS product, malicious hackers start beating on the code in that area to see if they can turn up other exploitable flaws. One might think, then, that MS would do the same. An integer overflow vulnerability was discovered in WMF file rendering in early Nov. '05 and the ISC has received submissions of examples of attacks exploiting the (later) SetAbortProc vulnerability that were apparently in circulation as early as mid-Nov (thus seeming to prove the first assumption above). So - how does this square with Fry Wilson's claim that the MS patch was "the fastest turnaround ever"? Was MS not beating on WMF rendering trying to find other flaws from early-Nov on? Were they so incompetent that they couldn't develop a fix, even though third-party coders had one in a couple of days after the public revelation in late-Dec? Or did they simply not care?

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread


Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

3 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters