Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 16, 2004

Critical Update for Windows Firewall Flies Under the Radar

RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
On December 14 Microsoft issued five new security bulletins. But as it turns out Microsoft issued another critical security update one day prior to their regular monthly bulletin release. A critical update for Windows Firewall that changes its behavior was released on December 13 and not announced to the public via the company's security bulletin service however the patch is listed at the company's Download Center.

According to Gary Schare, Product Director at Microsoft, the company only issues security bulletins for "code vulnerabilities" but didn't explain what constitutes such a vulnerability. It seems safe to assume that changes to software behavior due to previously unknown conditions--even if such changes are critical to enhanced security--will not be included in Microsoft security bulletins. Some people have expressed that they'd like to see such updates included in Microsoft's monthly security bulletins.

Those who do not keep the automatic update service constantly enabled or do not regularly visit the Download Center could remain unaware of the critical problem since the update isn't currently listed at any of the company's security-related Web sites.

Schare said that the company did post an article about the problem, "Making File and Printer Sharing Safer in Windows XP Service Pack 2," on their Windows XP home page back in September. The article offers tips on how to avoid exposing file and printer shares while using the Windows Firewall and the article will be updated to include information about the release of the update.

According to the related knowledge base article 886185 Windows Firewall users might find that after connecting to the Internet using a dialup connection that their machines are open to access by anyone, which explains the critical rating given to the patch by Microsoft.

When the firewall option "My network (subnet) only" is used Windows Firewall does not properly interpret local subnets. In some cases the firewall interprets the entire Internet as the local subnet. The error could lead to the exposure of all available system services including printer and file shares to anybody on the Internet. The KB article explains that this problem is due to the way some dialing software packages configure routing tables. Obviously anybody who relies on Windows Firewall for protection should download and install the update immediately.

In addition to the five new security bulletins issued on December 14 Microsoft also updated bulletin MS04-028, which relates to the JPEG Processing (GDI+) vulnerability, to inform customers that standalone updates are available for Microsoft .NET Framework 1.0 with SP2 and .NET Framework 1.1. Security updates are also available Visual FoxPro 8.0 including the runtime module. The company also released Windows Messenger 5.1 to fix the security issue related to bulletin MS04-28, as well as updated version of their Enterprise Update Scanning Tool .

On a more seasonal note, Microsoft released a new Christmas Theme for Windows XP users which includes "new wallpaper, animated cursors, new icons, new sounds and a 3D screensaver." Ho ho ho!

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
What You Need to Know About Microsoft's x64 Server Product Plans

What do Longhorn Server, Windows Compute Cluster Server, and Windows Vista have in common? The x64 platform. ...

Anti-Virus Vendors Prepare for War with Microsoft ... Again

When Microsoft announced its Windows Live OneCare security and PC health product over five years (as MSN OneCare), Symantec, McAfee, and the other consumer-oriented security vendors reacted with stunning vigor. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Related Events WinConnections and Microsoft® Exchange Connections

Security Summit

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Test Drive IT Solutions and Get Free Music Downloads
Solve your toughest IT problems with these free downloads and receive 5 free music downloads!


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home asp.netPRO Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing