Media Center
Microsoft is working on a patch for Media Center flaw

Microsoft admits to Media Center hole

Security flaw could allow hackers to crash PCs

Written by Iain Thomson

Microsoft is developing a patch for a newly discovered security flaw in versions of Windows XP which poses a particular threat to computers running XP Media Center edition.

The flaw is in Windows Remote Desktop Services (RDS) and could allow a hacker to cause a computer to crash repeatedly by sending specially crafted data packets.

Advertisement

Although all versions of XP have RDS, it is only turned on as standard in Media Center edition.

"Our investigation has determined that this is limited to a denial of service attack, so an attacker could not use this vulnerability to take complete control of a system," said Microsoft in a security advisory.

"Services that use the Remote Desktop Protocol are not enabled by default, but if a service were enabled an attacker could cause this system to restart."

Microsoft said that it will release a patch as soon as possible and is " aggressively investigating" reports of the flaw.

The user who discovered the vulnerability, security researcher Tom Ferris (aka 'badpack3t'), claims that he alerted Microsoft to the problem in May. The company told him that a patch would be released on 9 August as part of the usual monthly cycle

"I have been working with Microsoft to get a patch out for this," said Ferris. "Microsoft told me the patch was going to be released in August. We know it's only a DoS [denial of service attack], which is kind of boring, so this is why we decided to report it to Microsoft."

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Windows 7 screenshot

Microsoft defends choice of 'Windows 7'

But still does not satisfy Windows followers   More...

Apple MacBook

Apple rolls out new MacBooks

New case design and lower prices   More...

Novell UK office

Novell snaps up Managed Objects

Acquisition adds performance monitoring to Novell datacentre range   More...

Storage Expo

Better storage management key to success

Resource optimisation can offer a range of benefits, claims HP   More...

Primary Navigation