Newsletter:

Skip Navigation LinksHome > News > Security > Experts downplay Windows XP vulnerability

Experts downplay Windows XP vulnerability

By Shaun Nichols
2 November 2006 10:06AM
Tags: experts | downplay | windows | xp | vulnerability

Security firms say ICS flaw is not a major concern.

A recently discovered vulnerability in Windows XP that could lead to an attacker disabling a user's firewall is being downplayed by security experts who say that the flaw is "obscure" and "easily fixable".

The vulnerability lies within the Windows Internet Connection Service (ICS), a component that lets users share one computer's internet connection with other machines on a local area network (Lan).

When the ICS component crashes, the Windows Firewall is disabled as well, leaving the system vulnerable to attack, according to security company nCircle. The firm suggests disabling ICS to mitigate the risk. 

However, blogger George Ou at TechRepublic was critical of nCircle's solution, claiming that disabling ICS would also disable the Windows Firewall. 

The vulnerability itself is not a major problem either, according to security company Sunbelt Software.

Alex Eckelberry, president of Sunbelt Software, maintained that most users do not even use the ICS component.

He also pointed out that the attack would have to take place from a computer within the Lan, and that the vulnerability is not exploitable by any outside attack methods such as specially-crafted web pages or emails.

Sunbelt, Ou and security company Secunia all offer a simple fix for the vulnerability by using a router to share internet connections on a Lan rather than relying on ICS.

Copyright © 2008 vnunet.com

   


Ads by Google



Product Reviews

Star Rating
Paraben has been the market leader in hand-held forensics because the software is easy to use and covers a...
Star Rating
SpamTitan takes an interesting approach to managing spam.
Star Rating
Saint Scanner and Saint Exploit 6.7.11 are two great tools wrapped up to work together to provide an in-depth...
Star Rating
ManageEngine DeviceExpert 5.1 is a web-based configuration and change management solution for network...
Star Rating
The SPX3000 appliance from Array Networks combines many good features for making network resources easily...
TopTopics
(4854) -  google
(4568) -  internet
(4076) -  broadband
(3717) -  linux
(3671) -  iphone
(3477) -  security
(3350) -  mobile
(2135) -  government
(1592) -  china
(1589) -  telstra
(1156) -  ibm
(1078) -  microsoft
(991) -  apple
(942) -  network
(929) -  research