Microsoft Confirms Critical Win2K Flaw
Software engineers at Microsoft Corp.'s security research center on Thursday confirmed a potentially dangerous security hole in fully patched Windows 2000 systems that could put users at risk of malicious hacker attacks. The Redmond, Wash., software maker was forced to go public about the unpatched vulnerability after a private security research company posted details and proof-of-concept exploit code on the Internet.
According to an advisory from Israel's GreyMagic Software, the bug was detected in Windows Explorer, which allows users to navigate through the Windows file system by default.
GreyMagic discovered that the preview pane, or Web view, in Windows Explorer could be targeted to launch malicious code on machines running Windows 2000 Professional, Windows 2000 Server and Windows 2000 Advanced Server. Any other application that uses the Web View library under Windows 2000 is also vulnerable, the company warned.