|
|||||||
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 |
|
DriverHeaven Extreme Member
Join Date: Apr 2004
Posts: 7,275
Rep Power: 74 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Windows 98, ME users left vulnerable to WMF bug?
Microsoft on Thursday rushed out an update to address a serious security flaw in Windows. Patches are available for Windows 2000, Windows XP, and Windows Server 2003, but Microsoft left out Windows 98 and Windows Millennium Edition.
The flaw lies in the way the OS software handles Windows Meta File images. Microsoft deems the issue "critical" only for Windows 2000, Windows XP and Windows Server 2003, the problem is not as big for Windows XP and Windows ME because it is harder to exploit on those older OSes, the company said in its MS06-001 security bulletin.. Experts from iDefense, F-Secure and SANS agree that no attacks that target the older Windows versions have surfaced. Yet that might only be a matter of time, said Mike Murray, director of vulnerability and exposure research at nCircle, a vulnerability management company in San Francisco. Releasing a patch for Windows 98 and Windows ME would be the right thing to do, according to Murray. "Even Microsoft acknowledges that the vulnerability exists in those OSes, someone will figure out how to exploit it," he said. By not fixing the older versions of Windows, Microsoft is leaving its customers out in the cold, Murray said. "In a way they are forcing customers to upgrade, saying that you can continue to use those older operating systems if you want to be vulnerable," he said. ____________ Source: Security Blog (News.com) |
|
|
|
|
|
#2 |
|
DriverHeaven Extreme Member
Join Date: Jul 2002
Location: Real capital of Canada: Toronto
Posts: 5,515
Rep Power: 93 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Hello? Duh? Where has this guy been? Microsoft no longer supports Windows 9X/ME, and hasn't for a couple couple years now. Right thing or not, why should they spend resources to patch them if they no longer support those operating systems? That's like saying Microsoft should come out with Windows 3.11 USB drivers because people still use it (believe me, they still do). It's not worth Microsofts time, or money to keep supporting 5-7 year old operating systems (or older in some cases).
|
|
|
|
|
|
#3 |
|
DriverHeaven Extreme Member
Join Date: Apr 2004
Posts: 7,275
Rep Power: 74 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Actually, if you look at the Microsoft Support Lifecycle for Me, it says it's under extended support through 6/30/2006, and that critical security updates will be provided.
Critical security updates will be provided on the Windows Update site through June 30, 2006. http://support.microsoft.com/lifecycle/?p1=6519 The exact same sentence is on the 98 Support Lifecycle page http://support.microsoft.com/lifecycle/?p1=6513 |
|
|
|
|
|
#4 |
|
DriverHeaven Extreme Member
Join Date: Jul 2002
Location: Real capital of Canada: Toronto
Posts: 5,515
Rep Power: 93 ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Interesting. Didn't know that page existed. Thanks for pointing that out to me, Iria.
It is a bit misleading though. The way I see it is that they mean basic, and extended support for Windows ME and 98 have ended, but that Critical Update support will end June/06, and self help online support for ME will end June/07. Since this "technically" falls under "Critical Update" I guess "technically" they should release a fix for it. I doubt they will though. |
|
|
|
|
|
#5 |
|
Mostly lurking lately....
Join Date: Jun 2002
Location: U.S.A.
Posts: 2,032
Rep Power: 51 ![]() ![]() |
It may depend on how many people ask (or should I say beg) for it.....
__________________
|
|
|
|
|
|
#6 |
|
Flash Banner Hater
|
It appears that it is not classed as a critical vulnerability in the win9x family, as it cannot be exploited as directly - at least, they revised the advisory status for 9x as being non-critical.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|