News

Remote Code Execution Flaw Fixed in Windows

After burdening IT with patches for 20 vulnerabilities in its April Patch Tuesday, Microsoft offered a fix for just one vulnerability in this month's patch event.

The new vulnerability involves a flaw in the Windows Help and Support Center that could allow an attacker to remotely take complete control of a Windows XP or Windows Server 2003 system. Microsoft rated the flaw "important," one rung below "critical" on Microsoft's vulnerability severity scale. The flaw, detailed in security bulletin MS04-015, does not affect Windows 2000, Windows NT 4.0 or Windows 95/98/Me.

Although remote code execution flaws like this one are often rated critical, this vulnerability requires several responses from the potential victim, making it more difficult for an attacker to successfully execute and also difficult to automate. The attack is potentially most severe when the victimized user has administrative privileges on the system.

According to Microsoft, the flaw was discovered internally and there are no instances of anyone taking advantage of the problem so far.

The May version of Patch Tuesday, Microsoft's name for the second Tuesday of every month when it releases all its patches for the month, follows one of the most significant patch days Microsoft has ever done aside from a service pack or security rollup release.

In April, Microsoft released four security bulletins that covered 20 vulnerabilities, many of them critical. At least two of the vulnerabilities had been reported to Microsoft by outsiders more than six months before they were patched.

The security bulletin describing the flaw can be found here.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • World Map Image

    Microsoft Taps Nebius in $17B AI Infrastructure Deal To Alleviate Cloud Strain

    Microsoft has signed a five-year, $17.4 billion agreement with Amsterdam-based Nebius Group to expand its AI computing capabilities through third-party GPU infrastructure.

  • Microsoft Brings Copilot AI Into Viva Engage

    Microsoft 365 Copilot in Viva Engage is now generally available, extending Copilot's AI-powered assistant capabilities deeper into the Viva platform.

  • MIT Finds Only 1 in 20 AI Investments Translate into ROI

    Despite pouring billions into generative AI technologies, 95 percent of businesses have yet to see any measurable return on investment.

  • Report: Cost, Sustainability Drive DaaS Adoption Beyond Remote Work

    Gartner's 2025 Magic Quadrant for Desktop as a Service reveals that while secure remote access remains a key driver of DaaS adoption, a growing number of deployments now focus on broader efficiency goals.