Microsoft Corp. on Wednesday warned customers of a serious hole in all versions of Windows that could completely compromise a vulnerable machine.
The vulnerability lies in the DirectX technology that is included with Windows and is used to run multimedia presentations. One of the technology's components, DirectShow, contains two buffer overruns in the function that is used to check parameters in MIDI files.

An attacker who could create a malicious MIDI file and entice a user into opening it or visiting a Web page containing the file would be able to execute any code he chose on the user's machine. The code would run in the security context of the user.

The weakness affects several different versions of DirectX in various configurations and is the second serious problem to affect Windows Server 2003 in the past week. Microsoft last week had to issue a patch for a vulnerability in the Remote Procedure Call (RPC) protocol that handles message exchanges over TCP/IP. The vulnerability, which arises because of incorrect handling of error messages, affects a particular Distributed Component Object Model interface with RPC.

11,018 views 15 replies
Reply #1 Top
Thanks so much yrag for posting this here for all of us who need it...I love Xp as an OS, but I've never seen so many "security patches" for an OS - its a sieve! Hopefully LongHorn will be an improvement!
Reply #2 Top
Longhorn will have alot of security bugs or whatever when its new.

By time Longhorn comes out id imagine XP SP3 be out and it should be rock solid etc
Reply #3 Top
i prefer to have lot of patches than lot of unpatched holes.
Reply #4 Top
Your right Ian & Mr.XX of course....its just SEEMS every two weeks you read about another major "security hole" at the Neowin site about Xp - it would be nice to go a few months without one.
Reply #5 Top
The only problem is that *sometimes* the patch can hose your system and you then need a patch for the patch of the patch
Reply #6 Top
*cough* if any of you have a problem with security, get a mac *cough*

no, seriously!

(118 Days and not a single crash (PowerMac G4 DP1.25GHZ))
Reply #8 Top
I find the last two posts kinda questionable when placed into the context that this is WINcustomize.com

Reply #9 Top
Why did I expect these entries ?
Reply #10 Top
If you are REALLY concerned about security... get a typewriter.
Reply #11 Top
hm it's simpler if youre concerned about security is just to use a computer without any connections to internet.

that way you got all benefits of computer without any problems from connection to internet
Reply #13 Top
this isn't Xwincustomize.com

:rolleyes:
Reply #14 Top
...but still Windows has competition from Linux and Mac. They have had great influence on Windows skinning. The Crystal icons originated on Linux. Aqua skins originated on Macs.
Reply #15 Top
not denying that .. but this is hardly the place to be all preachy about alternative OSes, due to the fact that this is a windows skinning website.. It would be more appropiate to go to slashdot