Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Zero-day WMF flaw underscores patch problems
Robert Lemos, SecurityFocus 2006-01-12

For four days in January, network administrators and security-savvy home users had a choice: Download and install an unofficial open-source fix for the critical flaw in the Windows Meta File (WMF) format or wait an estimated week for an official patch from Microsoft.

Comments Mode:
What Microsoft needs to be doing... 2006-01-12
Eric (2 replies)
What Microsoft needs to be doing is going back through the existing code in their current Operating Systems and finding the vulnerabilities BEFORE someone else does. That way they can roll out security fixes as part of their regular schedule and yet we can, for the most part, be safe from 0-day exploits.

My guess is this is due to their history as a top-down rather than customer-driven company. Rather than looking out for the best interests of the customers they are thinking of what will give them the next big injection of cash; that, of course, is Vista. Because of this an inordinate amount of their resources are spent on Vista, rather than finding and fixing vulnerabilities in the current code.

In the long term this diminishes their reputation in the market, driving more people to other Operating Systems. By emphasizing profits ahead of customers and employees they do themselves more harm than any blackhats ever could.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11368/32950#32950
Re: What Microsoft needs to be doing... 2006-01-13
Matthew Murphy (1 replies)
Alternative solution 2006-01-13
mxb (2 replies)
Re: Alternative solution 2006-01-13
DSMatthews
Re: Alternative solution 2006-01-13
Anonymous
Make'em pay! 2006-01-13
assurbanipal
The Squander of MS Admins && Users 2006-01-13
Anonymous (1 replies)
Re: The Squander of MS Admins && Users 2006-01-16
Anonymous (1 replies)
Does any one see this 2006-01-13
Anonymous
Patch from Guilfanov was not the only one 2006-01-16
Juha-Matti Laurio







 

Privacy Statement
Copyright 2009, SecurityFocus