Microsoft Rushes to Fix Critical XP Flaw
By Nate Mook | Published July 18, 2005, 2:01 PM
Microsoft is rushing to patch a critical flaw in the Windows Remote Desktop Service, which affects fully updated Windows XP machines. The problem could be exploited by an attacker to cause a denial of service attack that crashes the PC with a Windows "blue screen of death."
Microsoft was informed of the flaw on May 4, and plans to issue a patch in its August security bulletin. The problem was discovered by Security Protocols, which posted a screenshot of a system being crashed.
"The issue was originally privately reported to Microsoft and we are working on an update that will be released when it is of the appropriate quality," a Microsoft spokesperson said. "The concern is that this has now gone public, potentially putting customers at risk."
Company officials said, however, that there was little risk in code being executed on a remote machine. The DoS attack would simply overload the Remote Desktop service and cause a PC to stop responding.
Windows 2000 Service Pack 4 and Windows Server 2003 are also potentially affected, Microsoft said.
Security firm Secunia has rated the problem "moderately critical" in an advisory. The firm noted that Remote Desktop is disabled by default on all Windows XP systems, except XP Media Center Edition. As a temporary solution, users can disable the service.
Contrast Mr Mook's headline for this article to the headlines he writes for his Firefox/Mozilla articles. Taking two months to fix a critical flaw in Windows is "rushing", finding flaws with extensions in Firefox raises issues about the browser's integrity and security. I think Mr Mook should either show a little more objectivity or admit he evangelizes for Microspud
Score: 0
|Whats new with MS??
Score: 0
|I detest these semi-illirates who hide behind screen names .Have their diapers leaked ? Why do you allow their insipid comments ? Is Beta News a spokesperson for the prepuscent crowd . If it is, count me out. Otherwise restrict your comments to cogent,salient, literate opinions. These people belong in the Mickey MOUSE CLUB
Score: 0
|AS MICROSOFT STRUGGLES WITH FLAWS AND FIREFOX HAS TO RECALL THEIR NEWEST RELEASE WHO CAN WE TRUST ? GOOGLE, MAYBE ? WHY IS THEIR SOFTWARE FAULTLESS ? WHY IS GOOGLE EARTH SUCH AN EYE-POPPING,IMAGINATIVE SOFTWARE ? PROBABLY BECAUSE THEY ARE YOUNG UNBRIDLED BY GREED AND WILLING TO GO WHERE NO ONE HAS EVER GONE "REMEMBER MICROSOFT?" THE ATT OF COMPUTING. BREAK IT UP
Score: 0
|someone just found the caps lock key
Score: 0
|ok, let me get this straight. They were warned about this over 2 months ago, now they are saying it's going to be another month before a patch is out. This is called rushing???? It's not that big of a deal since this feature can be disabled but it the principle of the thing that bothers me.
Score: 0
|Ahh, well, you know microsoft. There's a bug, so they issue a temporary hotfix within a year, and then fix the issue in the next OS, or the one after that.
Score: 0
|I still have an original windows 1.1 on some floppy,s
Score: 0
|You people are SOOO clueless!!!
Remote desktop is not what allows Microsoft to come in and "assist you",... THAT would be Remote Assistance.
The service IS ALREADY disabled, BY DEFAULT.
The service is in NO WAY a "virus service".
Terminal Services IS Remote Desktop(RDP).
Score: 0
|OHHH my GOSSSSH you are SOOOOOOOOO right!
*rolls eyes*
How old are you again? Honest question.
Score: 0
|Score: 0
|It is a "virus service"--it is mysteriously enabled once malware comes in--that's why many virus infected PC's are so hard to fix. It's not removing viruses that's hard--it's all the registry settings you have to fix. Seriously though you are correct it is disabled by default, but many programs ENABLE it, many P2P software does...
Score: 0
|erickufrin is an anagram of INRI ****er
Score: 0
|Yes, this is why I have this service disabled. Even the thought of the option for someone at MS to log in to my box to "assist me", uh-uh.
I can see the feature useful on a private network, but even then, no thanks.
Score: 0
|That's not what this is--you're probably thinking of Remote Assistance, but even THAT isn't what this is. Microsoft won't take control of your machine--you send an "invite" to whomever you want, such as a techie friend.
Remote Desktop is like VNC, but it can actually be a bit more useful, as it includes sound and some other neat things that VNC wouldn't "catch."
Score: 0
|Sound on remote desktop??
please teach me how to turn it on :)
Score: 0
|If MS was informed in May, how can they say they're "rushing" to fix this? Shouldn't the patch have been made available at the very next set of updates? Oh yeah sure... 'they've been working on it'. Uh huh.
Score: 0
|Good little article
Score: 0
|That settles it. I'm going back to DOS 3.3 and that's final.
Score: 0
|No no! Don't do that! Go to OS/2 if anything.
Score: 0
|I have 6.22 if you really need it. LOL
Score: 0
|Don't do that, IBM recently announced they are dropping support for OS/2 at the end of this year.
Score: 0
|Ok, then go to OpenDos instead. :D
Score: 0
|IBM has been out of the picture in OS/2 for several years now. Serenity Systems now does the OS/2 systems releases and will most likely be doing the updates soon as well. IBM licenses serenity systems to do OS/2 at least 4 years ago and washed their hands of it.
Score: 0
|Anyone know if this applys to Win 2k3 Terminal Services, I believe it is pretty much the same technology as RDP?
Score: 0
|Remote Desktop is Microsoft's revised name of Terminal Services. I would bet that if this problem exists in XP then it does in Windows 2K3.
Score: 0
|Good little article...concise,to-the-point!
Be well.......
Score: 0
|Like with all computers I work on, I disable that service from the start.
Score: 0
|Absolutely. That service is one of the [in]famous "virus services" if not needed don't leave it enabled.
Score: 0
|Really? Please elaborate.
What about the Remote Desktop service qualifies it as a famous "virus service"? Are you aware of any specific viruses that have propagated through RDP? Has it been a known point of intrusion for hacking and if so how?
I've seen some DoS attacks against RDP, I've personally have never heard it related to anything involving "viruses" so I'm curious as to what you've found.
Score: 0
|gawd21,
It already IS disabled by default!
Anyone who has enabled it, obviously uses the function.
Score: 0
|No it's not if you have Windows Messenger installed and have not changed it in the system properties.
Score: 0
|Mostly trojans. It is also usually enabled by trojans if not already, it is very useful for propogating data quickly accross computers, of course except that it is disabled by default...I've seen many of the SDBOT, RBOT, and a couple of AGOBOT variants use this service to propogate to other vulnerable machines. A big one is IMASERV, though, which is why I hated symantec as it did not detect that one varient with 2003 or 2004 (yes the COORPORATE version did but home users...well...) I had to explain to countless users that the reason viruses kept infecting their system is because there was one that Norton did not remove that "left the door open" for others to flood in. Symantec is finally removing the varient now, thank God.
I admit I deal with fixing home user's computers more than anything, and that's where this service is most painful. Networks thank goodness can disable it and keep it disabled via network policy, etc.
Score: 0
|Are you confusing Remote Desktop with Windows Messaging Service? Windows Messaging Service is a source of pop-ups that can infect PCs. Remote Desktop is a remote control utility that one must turn on before you use it. And you require a valid user name to access the PC.
Score: 0
|