Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No
Ads

Microsoft Patching 17-year-old Windows/DOS Bug

by - source: Tom's Hardware US

A patch is on the way to fix up that ancient Virtual DOS Machine flaw.

Last month we reported that Tavis Ormandy, a security researcher at Google, discovered a security flaw in the Virtual DOS Machine that can allow a nefarious user to inject code into the kernel and possibly install malware.

The flaw spanned iterations of Windows operating system over the last 17 years, including:

  • Windows 2000
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Windows 7

According to the BBC, Microsoft will be rolling out a fix to this bug in a February Security Update. The update will fix five vulnerabilities that allow attackers to hijack a Windows PC and run their own programs on it.

The patch is expected to hit on Tuesday, February 9 but it's a good idea to have automatic updates turned on so that your OS will do the checking for you.

Share:
50
Comments
X
Submit

Comments
Add your comment
fafner 02/05/2010 10:20 PM
Hide
-18+

Yay, 4 more days for hackers to have fun with it.

pink315 02/05/2010 10:21 PM
Hide
-20+

Time to boot up my Windows 3.1 System for updates

idisarmu 02/05/2010 10:23 PM
Hide
--1+

kernal???

Use spell check please.

xbeater 02/05/2010 10:30 PM
Show
xbeater 02/05/2010 10:32 PM
Show
Ehsan w 02/05/2010 10:38 PM
Hide
-2+

yay
they finally fixed it.

Hellbound 02/05/2010 10:38 PM
Hide
-16+

Better late then never I guess....

davendork 02/05/2010 10:38 PM
Hide
-0+

MSFT is rocking the code reuse. OOP is FTL?

Shadow703793 02/05/2010 10:43 PM
Hide
-19+

Hmm... you mention Server 2008 but not Server 2008 R2 but yet you mention Vista and Win 7?

========

One more thing: This ONLY affects 32 bit Windows Versions!
See: http://www.microsoft.com/technet/s [...] 79682.mspx

=======
Affected Software

Microsoft Windows 2000 Service Pack 4

Windows XP Service Pack 2 and Windows XP Service Pack 3

Windows Server 2003 Service Pack 2

Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2

Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2*

Windows 7 for 32-bit Systems
Non-Affected Software

Windows XP Professional x64 Edition Service Pack 2

Windows Server 2003 x64 Edition Service Pack 2

Windows Server 2003 with SP2 for Itanium-based Systems

Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2

Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2

Windows 7 for x64-based Systems

Windows Server 2008 R2 for x64-based Systems

Windows Server 2008 R2 for Itanium-based Systems

Anonymous 02/05/2010 10:57 PM
Show
warmon6 02/05/2010 10:58 PM
Hide
-6+

xbeater :
oh but I though windows 7 was entirely rewritten from scratch......sons of b***es been lying to us AGAIN!!!



Some how i dont think they lie. In fact they never mentioned it was rewritten.

it certainly improved coding from windows vista but not rewritten.

warmon6 02/05/2010 10:59 PM
Hide
-3+

Shadow703793 :
Hmm... you mention Server 2008 but not Server 2008 R2 but yet you mention Vista and Win 7?========One more thing: This ONLY affects 32 bit Windows Versions!See: http://www.microsoft.com/technet/s [...] 79682.mspx=======Affected SoftwareMicrosoft Windows 2000 Service Pack 4Windows XP Service Pack 2 and Windows XP Service Pack 3Windows Server 2003 Service Pack 2Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2*Windows 7 for 32-bit SystemsNon-Affected SoftwareWindows XP Professional x64 Edition Service Pack 2Windows Server 2003 x64 Edition Service Pack 2Windows Server 2003 with SP2 for Itanium-based SystemsWindows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2Windows 7 for x64-based SystemsWindows Server 2008 R2 for x64-based SystemsWindows Server 2008 R2 for Itanium-based Systems



+1 nice find shadow.

Yuka 02/05/2010 11:00 PM
Show
dwave 02/05/2010 11:03 PM
Hide
-3+

Good job getting that fixed in a timely fashion!

hakesterman 02/05/2010 11:12 PM
Hide
-2+

And what are they going to do on your PC? Play Solitaire!

hakesterman 02/05/2010 11:19 PM
Hide
-2+

Microsoft never stated that Windows 7 was written from scratch, you must of dreamed that. Windows
7 is a Vista make over. They took vista and deleted all the main complaints and added the top features
everyone suggested. Any 64 bit driver that was written for Vista will work with 64 bit Win 7, i have downloaded and used 6 Vista drivers for my Windows 7 including but not limited to Printer, and they all
work perfectly. This is such a small hacker risk that Microsoft didn't feel the need to address it till now, and
probably the only reason their addressing it is to shut a few people up. Go Windows 7(Vista)...........

Shadow703793 02/05/2010 11:51 PM
Hide
-7+

dweaver :
Get rid of Windows, use Linux :-)


I would love to, but unfortunately I need Windows to play me games (ie Crysis, Far Cry,etc).

Razor512 02/05/2010 11:55 PM
Hide
--1+


yep, programming is hard so it is understandable, taking 17 years to patch a security problem, especially when your busy making the OS slower and adding useless eye candy.

Microsofts response to taking 17 years
"Do you want it done fast or do you want it done right"
:)

maestintaolius 02/06/2010 12:13 PM
Hide
-2+

pink315 :
Time to boot up my Windows 3.1 System for updates


heh, +1 good sir.

fafner 02/06/2010 1:39 AM
Hide
--1+

Shadow703793 wrote :

I would love to, but unfortunately I need Windows to play me games (ie Crysis, Far Cry,etc).





http://www.youtube.com/watch?v=USni2nTweOE

Not sure how well it works tho.

Shadow703793 02/06/2010 1:43 AM
Hide
-2+

fafner :
http://www.youtube.com/watch?v=USni2nTweOENot sure how well it works tho.


Doesn't work well at all unless you enjoy 1024*720 and slide shows.

digitalrazoe 02/06/2010 2:53 AM
Hide
-1+

Only took 17 years...

slayerz636 02/06/2010 3:28 AM
Hide
-0+

pink315 :
Time to boot up my Windows 3.1 System for updates


yeah its about damn time, was i the only one that caught this 17 years ago? lmao jk

cmartin011 02/06/2010 7:43 AM
Hide
-1+

Shadow703793 good work. I'm glad i took advantage of the 64 bit environment they actually had to really start from scratch with this peace of code

martijnmp 02/06/2010 11:03 AM
Hide
-0+

This bug must have been a 17-year Cicada...

http://en.wikipedia.org/wiki/Magicicada

JohnnyLucky 02/06/2010 1:28 PM
Hide
-0+

must not have been much of a bug.

mp562 02/06/2010 5:10 PM
Hide
--3+

idisarmu :
kernal???Use spell check please.


Maybe you should take your own advice.

Judguh 02/06/2010 5:17 PM
Hide
--1+

stoppostingcrapnews :
Well at least they're doing something about rather than do nothing.



There WERE just doing nothing about it. Now FINALLY they're doing something about it!

extremepcs 02/06/2010 5:42 PM
Show
cookoy 02/06/2010 6:33 PM
Hide
-0+

Take a researcher from a competitor to finally persuade MS to act.
Friendly competition benefits us all.

rammar16 02/06/2010 7:02 PM
Hide
--1+

better late than never?


Ads

Best offers

Newsletters


OK
Ads