Windows XP: bugs
Published: 24 May 2002
Microsoft would have us believe that XP is the most secure operating system it has released to date. But the nine security updates the company has released since XP's launch belie that claim.
In fact, one problem -- buffer overrun vulnerabilities in Internet Explorer and Universal Plug and Play (UPnP) -- poses such a severe threat that the FBI got involved. Microsoft says that a hole in the Plug and Play software could conceivably allow a malicious hacker to take complete control of your PC. Worse, the security hole applied to every XP user -- the OS ships with Universal Plug and Play turned on by default. Don't have the patch yet? Get it now at Microsoft's TechNet site. Additional new security patches include a fix for the Microsoft Java Virtual Machine, which, if left unpatched, can let Java applets from Web sites silently reroute all browser traffic to the applet's host without the user's knowledge. Yet another patch fixes an ‘Unchecked buffer in the Multiple UNC Provider’, a problem that allows a hacker to send a malformed data request to a PC to either run programs at will or cause the computer to restart. Click Start > Programs and run Windows Update to access all the available patches.

So far, the most secure aspect of Windows XP's networking lies in the built-in software firewall. Unfortunately, though, that firewall can prevent some Microsoft online services, particularly Windows Update and even XP Professional's Remote Assistance tool, from working properly. We prefer a third-party product such as ZoneAlarm or Norton Internet Security.
Interestingly, none of XP's security updates have anything to do with the once-feared raw sockets support included in XP's TCP/IP network protocol drivers. Many sceptics believed that XP's raw sockets support posed a security threat because it allows programmers to generate data transmissions from one computer and make them appear to come from a different one -- a technique used in distributed denial-of-service attacks.
Test Your Desktop Management Systems
How good are your company's desktop management solutions? How do they compare with those of your peers?
Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.
Skip Sub Navigation Links to CNET Brand Links
- Security threats
- Mobile devices
- Application development
- Network management
- Desktop platforms
- Security management
- Databases
- Processors
- Server platforms
- Storage
- Mobile working
- Office applications
- After hours
- Mail & messaging
- Training
- Disaster recovery
- Enterprise applications
- VoIP
- Emerging tech
- Green IT
- Outsourcing
- Virtualisation
- SME
- Enterprise open source
- Industry watch
- Online business
- Accessibility
- Management
- Intellectual property
- Compliance
Home
- Site Map
- RSS Feeds
- Content Archive
- ZDNet.co.uk Mobile
- Search Library
Membership
- Log in
- Register
- Forgotten Password
- Membership benefits
- Newsletters
About Us
- Contact Us
- Find Us
- Privacy Policy
- Permissions and Reprints
- International
- Advertise
News
- Hardware News
- Software News
- Communications News
- Internet News
- Security News
- IT Management News
- Emerging Technology News
- Leaders
Blogs
Group Blogs
- News blog
- Reviews blog
- Not Safe For Work blog
- Rupert's Diary blog
- Sentry Posts blog
- Vista Upgrade blog
- On The Road blog
- Homebrew blog
- Post Room blog
- Uptime blog
ZDNet UK Staff Blogs
- Rupert Goodwins
- Charles McLellan
- David Meyer
- Tom Espiner
- Colin Barker
- Karen Friar
Core Techs Expert Blogs
- Adrian Bridgwater
- Peter Judge
- Christian Harris
Tech Community
- Top 100 ZDNet UK Members
- My ZDNet Tour
- Forums
- Competitions
- Community FAQs
Benchmarks
- Business Value benchmark
- Server Value benchmark
- Desktop Management benchmark
- Mobile Security benchmark
White Papers
- Most Popular white papers
Free Software Downloads
- Windows downloads
- Mac downloads
- Mobile downloads
- iPhone Apps downloads
Reviews
Hardware reviews
- Accessory reviews
- Audio reviews
- Component reviews
- Desktop reviews
- Handheld reviews
- Imaging reviews
- Input Device reviews
- Mobile Phone reviews
- Monitor reviews
- Netbook reviews
- Networking reviews
- Notebook reviews
- Printer reviews
- Projector reviews
- Server reviews
- Storage reviews
Software reviews
- Content Creation reviews
- Developer Tool reviews
- Enterprise Application reviews
- Operating System reviews
- Productivity software reviews
- Security reviews
- Utility reviews
- Editor's Choice reviews
- Buyer's Guides
- Tech Guides
Tech Resources
- Company Pages
- Technology Events
- Research Panel
- IT Jobs
Articles
- Case Studies
- Comment
- FAQs Articles
- Features
- Image Galleries
- Tutorials
- Video stories
- Research
Compare Prices
- Laptop prices
- Cheap Laptops
- Desktop prices
- Mac laptop prices
- Mac desktop prices
- Tablet PCs prices
- PDA prices
- Printer prices
- Printer cartridges prices
- Scanner prices
- Monitor prices
- Windows oftware prices
- Server prices
Special Features
- Broadband Speed Test
- CIO Vision Series
- Dialogue Box
Advertising Features
- Intel Make the Case







