Microsoft Investigating New Windows Vulnerability
Everyone has different reasons for exposing Windows security flaws. Some do it for avenging a fellow security researcher's insult, others to bring home the bacon. Unlike the Microsoft -Spurned Researcher Collective, which falls in the former category, Danish security firm Secunia's motivation is purely pecuniary.
Secunia on Monday issued an advisory detailing a newly discovered vulnerability in Windows. The moderately critical vulnerability is caused due to an error in the mfc42.dll, and effects fully patched versions of Windows 2000 and Windows XP.
“The vulnerability is caused due to a boundary error in the "UpdateFrameTitleForDocument()" function of the CFrameWnd class in mfc42.dll. This can be exploited to cause a stack-based buffer overflow by passing an overly long title string argument to the affected function,” Secunia said on its site.
According to group manager Jerry Bryant, “Microsoft is investigating new public claims of a possible vulnerability in Windows 2000 and Windows XP.” However, he is unaware of any attacks based on the vulnerability.

Comments
Comments are closed on this article
![]()
Lhot
July 07, 2010 at 1:07pm
What a coincidence...MS laying off employees....and security researchers STILL finding (supposed) security flaws in Windows XP, even after TEN years of use. This is just more "buy Windows 7 hype" if you ask me. I've run Win XP since it came out and with minimal effort have never gotten a virus or trojan....and I surf EVERYwhere....even the bad places.
I am getting so tired of MS and those obviously paid by MS to diss XP....that it isn't even funny.
The "CLOUD" is the biggest mistake this country has made...EVER !
Log in to MaximumPC directly or log in using Facebook
Forgot your username or password?
Click here for help.
















