NEWS

Microsoft, McAfee, Firefox Fix Security Loopholes

May 23, 2010 6:43 PM

James Mulroy

Internet_Security_1.jpeg

The bugs keep marching in, with Microsoft, McAfee, and Mozilla all having to deal with serious security-related software problems in the past month.

Another Windows Fix

According to Microsoft, "two privately reported vulnerabilities in Windows Authenticode Verification...could allow remote code execution." In other words, an attacker could take control of your PC by exploiting either of those flaws. The intruder could gain administrator rights, with the ability to add, change, or delete practically any file.

Microsoft has issued an update that addresses the vulnerabilities by performing additional verification operations. This update is critical to all supported versions of Windows, including 98, XP, Vista, and 7, as well as Server 2003, 2008, 2008 R2, 2003, 2000, and 2000 Professional.

If you have automatic updates enabled (recommended), you'll get this update and others instantly. If you do not have automatic updating turned on, Microsoft suggests downloading critical updates manually; go to the Control Panel, click the Windows Update icon, and then select Check for Updates. You can learn more about this patch, and download it manually, at Microsoft TechNet.

McAfee Update Makes Windows PCs Crash

McAfee released an update in mid-April that unfortunately caused Windows PCs to fail spectacularly. The update improperly identified a Windows component known as svchost.exe as a virus, which caused McAfee's software to delete it.

The error was so severe that 8000 of the 25,000 computers at the University of Michigan Health System and Medical School crashed, along with thousands of computers around the world.

Put simply, svchost.exe is a process that hosts other services used by various programs on your PC (read Microsoft's explanation for more-technical details). If you look in Windows Task Manager, you may see quite a few svchost.exe processes running (under "Image Name"), and as you can imagine, attacking all of them could be catastrophic for any system.

The problematic update mostly affected users running Windows XP Service Pack 3. If it affected you, pick up McAfee's SuperDAT Remediation Tool to restore svchost.exe.

Firefox Flaw Corrected

A hole in the Mozilla Firefox Web browser has blossomed into a major flaw. A week after releasing Firefox 3.6.2, Mozilla released version 3.6.3 to address a critical security issue that could allow remote attackers to run commands of their choice.

To fix the bug, download Firefox 3.6.3, or click Help, Check for Updates, Get the New Version in the Firefox toolbar. Mozilla says the bug does not affect versions 3.5 or earlier.

If you still want to obtain and use add-ons that are not compatible with version 3.6, don't worry: Mozilla says that it will issue a patch for Firefox 3.5 in an upcoming release in case another method of exploiting this security hole exists.

 

ALSO READ

FTC wants to keep closer watch on the Internet of Things

As technology plays a bigger role in running our homes, connecting our cars, and handling our finances, the Federal Trade Commission wants to keep a closer watch on the privacy and security implications.

Twitter partners with Foursquare to add precise locations to tweets

Twitter is about to catch up to Facebook circa 2011. The self-styled information network recently announced it will partner with Foursquare to let you tag your tweets with specific locations. Until now, including your location in a tweet only added the general area you were in, such as a city or rural county.

Vessel is a slick new streaming service with a focus on Internet stars

A new streaming service called Vessel is trying to take on YouTube, but without the clutter of user-generated videos.

First exclusively live-streamed regular season NFL game to hit next season

The National Football League has a long way to go before it can match the live streaming chops of pro baseball, but the NFL's online offerings have been getting a little bit better every season. When the 2015-16 season starts up this fall, the NFL will reportedly try an experiment that could have major implications for cord cutters.

The IControl One adds new capabilities to old home-security systems

If you're a longtime customer of an independent home-security firm, there's a good chance your system's control panel will soon need a major upgrade. That's because companies such as AT&T, Verizon, and others are gradually shutting down their 2G cellular networks to make room for faster and more efficient 3G and 4G networks.

Expert Opinion

fadell-nest-100254262-orig_500.jpg

Apple doesn't need its own gadgets to dominate the smart home

If you believe the weekend rumors, Apple will announce a connected-home platform next week at WWDC. But before you get too excited about an iThermostat and an iFridge and an iCamera watching you sleep, consider this: If Apple does get into the home-automation market, that doesn't necessarily mean it'll make smart-home gadgets of its own.

Editors Pick

justin_tv-100367814-orig_500.jpg

Justin.tv goes off the air

With all signs pointing to a Google purchase of Twitch, the company behind Justin.tv has shut down the live video service.

my_verizon_mobile-100367793-orig_500.png

Verizon fires back at FCC over data throttling

The FCC called out Verizon for its plans to throttle customers with unlimited data plans who use the most data, so the carrier responded.

unionstreet_yelp-100366548-orig_500.png

Business faces backlash after threatening $500 fines for negative Yelp reviews

Businesses who don't know how to manage their social media presence should remember that the Internet can be vicious.

Latest Product Reviews

key-ingredient-tablet-100566733-orig_500.png

Key Ingredient kitchen tablet review: Yummy recipes can't rescue this crummy tablet

Meatballs. Giant bacon-wrapped meatballs. The Key Ingredient Recipe tablet suggested this fantastic idea to me when I searched for a meatball recipe. It's a good thing the meatballs were tasty, because that's about the only thing this tablet gets right.