04.25.10

Microsoft Serves Patch to Windows Servers Which Can Compromise These Servers Rather Than Secure Them

Posted in Boycott Novell, Microsoft, Security, Servers, Vista 7, Windows at 6:12 am by Dr. Roy Schestowitz

Antique hammers

Summary: Latest Windows Update can actually create holes rather than close them; Vista 7 is disliked by another business, which may dump it for another operation system (or XP)

MICROSOFT IS not so good at patching those serious flaws which it deliberately hides; every now and then we find a story about Microsoft delivering bad patches that break Windows rather than fix it (sometimes even breaking mathematics in Office). Microsoft then issues a patch to fix the damage caused by the first patch, assuming that Windows can boot at all or connect to the network after the first patch.

According to this report, Microsoft has just done that again and it’s retracting the patch (a little too late though).

Microsoft has withdrawn an update for Windows Server because the patch, issued eight days ago, does not treat the root cause of the problem it was meant to fix.

This is why so many users — including businesses — refuse to accept Windows patches, at least immediately (some take a wait-and-see approach). They have no confidence in them.

As Terry Porter put it, “Windows Server fix pulled after failing to patch flaws.” He cites this interesting article which goes further than the above.

Windows Server fix pulled after failing to patch flaws.

Microsoft has taken down a recent security patch for Windows 2000 Server.

The company said that it would be working on an update for the MS10-025 patch, released last week as part of the monthly ‘Patch Tuesday’ update package.

The update was taken down amidst reports that the fix Microsoft had released was not properly patching vulnerabilities in the Windows Media Services component for Windows 200 Server.

The company has the vulnerabilities rated as ‘critical,’ and a successful update could allow an attacker to remotely execute code on a targeted system. No attacks targeting the flaw have been reported in the wild, however.

Be sure to read that last part again. It says that “a successful update could allow an attacker to remotely execute code on a targeted system.”

Gotta love Windows, eh?

“Business is far too important to entrust to Windows, get a clue and look at GNU/Linux TODAY!”
      –Terry Porter
Porter has actually shared another anecdote, quoting what he titled “Windows 7 described as a disaster by small business owner, may switch to another OS!

“This business user had Autocad,” he explains, “and MS Word compatibility problems,  no  printer drivers for a hp DeskJet 5850 (which is supported under Linux),  and describes his Windows 7 purchase as a “disaster”.

“Business is far too important to entrust to Windows, get a clue and look  at GNU/Linux TODAY!”

Here is the word directly from the source:

We [purchased] a new fully loaded HP desktop (three months ago) with all the goodies,” they wrote. “We are experiencing to many problems to list but here are some; video very unstable, incompatibility problems with ACAD 14, MS Word 2003, Macromedia drivers, Easy Innkeeper etc., etc. not working at all or unstable, Microsoft Outlook 8 irregular load failures and no drivers for hp DeskJet 5850 (it will only work as a network printer).

We are small business owners and this is a disaster of a purchase we 
made.

We replaced our older HP Pavilion f1905 running XP pro/service pack 3 (hard drive problems) with an E154 running on Windows 7 Pro. They (MS) still do not get it – we do not have an IT department and service calls are getting expense. HP service technicians have been of very little help. We will be seriously looking at switching to brand X or go back to XP.

Why does Microsoft keep saying that everyone loves Vista 7 when obviously that’s not true?

Battery icon

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

This post is also available in Gemini over at:

gemini://gemini.techrights.org/2010/04/25/creating-holes-not-closing-them/

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. Yuhong Bao said,

    April 25, 2010 at 8:58 pm

    Gravatar

    “Be sure to read that last part again. It says that “a successful update could allow an attacker to remotely execute code on a targeted system.””
    On the matter of this, remember MS06-042, which in some OSes introduced a vulnerablity, and it required two revisions before that was finally patched properly?

What Else is New


  1. For 17 Days (and Counting) António Campinos Has Failed to Respond to Call for Compliance With the Law

    Team Campinos has been so arrogant and so evasive that there’s no indication (yet) that it will follow court orders (Willy ‘Guillaume’ Minnoye openly bragged about ignoring court orders and he's still cheering for the EPO's abuses); therefore, staff of the EPO takes collective action



  2. Raw: Elodie Bergot Breaking the Law by Threatening Against the Exercise of Fundamental Rights

    Over the years we saw a number of rude letters from Elodie Bergot, the grossly under-qualified spouse of a friend of Vichyite Benoît Battistelli; most of these we never published (we already have these and can always publish if the need arises), but those paranoid and insecure “Mafia”-like ‘cabal’ need to be exposed for the mobsters they are; for nearly a decade they’ve illegally bullied EPO staff in clear violation of the law (and for over 3 years António Campinos has kept those bullies on board); why does Europe do nothing and why is it never holding high-profile abusers accountable (only low-level facilitators)? Is it because the EU too is being infiltrated by them?



  3. Linspire Should Be Avoided in 2021 Just Like It Was Avoided 14 Years Ago

    The brand "Linspire" was brought back, but the agenda seems to be more or less the same, namely pushing proprietary software and serving Microsoft's commercial agenda (in 'Linux' clothing)



  4. The Death of Freenode Would Be Freenode's Own Fault

    Freenode is going dark and now it’s asking people to create accounts at IRC.com (just to get back into the network that they may have already occupied for decades) as if Freenode owns “IRC” as a whole



  5. Links 31/7/2021: KDE Progress and Activision Catastrophe

    Links for the day



  6. IRC Proceedings: Friday, July 30, 2021

    IRC logs for Friday, July 30, 2021



  7. The Smartest Meter of All

    Yesterday a lady came over to take our power readings (electric/gas meter); secure these people's jobs as they help protect people's privacy (dignity) at home



  8. [Meme] A Web of False Dichotomies

    A reminder that Techrights is fully available (all blog posts and wiki pages) in gemini://



  9. Freenode Shrinks by Another Quarter and Gemini Continues to Grow (For Techrights at Least)

    Freenode continues to perish faster than we've imagined; it's a good thing that we've had contingencies set up; regarding the monopolised and increasingly centralised Web, we're still making baby steps towards weaning ourselves off it



  10. Links 31/7/2021: Wine 6.14 and Chrome 93 Beta

    Links for the day



  11. European Media Does Not Care About Europe's Second-Largest Institution Crushing Basic Laws and Fundamental Rights

    New video about the latest publication from SUEPO (the EPO’s staff union); it was published yesterday, seeing that the “Mafia” (what EPO staff actually calls the management!) hasn’t done anything to comply with a wide-ranging set of court rulings from ILO-AT; why has the media said nothing about this and what does that say about today’s media? The material is all in the public domain, in widely understood languages, and SUEPO spoke about it more than 3 weeks ago.



  12. Links 30/7/2021: Distro Comparisons and Tootle Introduced

    Links for the day



  13. [Meme] Enforcing ILO-AT Rulings...

    We’re still waiting for a statement — any statement (direct or indirect) — from EPO management, seeing that almost a month has passed



  14. 'Open Source' as a Failed Initiative

    A closer look at the dire state of the Open Source Initiative, or OSI, which no longer protects Open Source (let alone software freedom) but instead helps openwashing, Microsoft entrapment, and a coup against the FSF



  15. [Meme] Rowan and António Sittin' on a Tree...

    How much longer can Team Campinos keep issuing tons of noisy and self-congratulatory puff pieces to (perhaps) distract from the elephant in the 10th floor of the Isar building (EPO HQ)? Staff won't wait for eternity.



  16. IRC Proceedings: Thursday, July 29, 2021

    IRC logs for Thursday, July 29, 2021



  17. Half the People in This Letter Are IBM Employees

    IBM seems to be continuing its war on the FSF because IBM wants to own everything (CentOS being ‘canned’ was just part of the plan)



  18. The OSI Song

    The sad demise of OSI, which has become little but a front group of proprietary software companies in pursuit of openwashing services (and outsourcing to proprietary disservices looking to eradicate copyleft)



  19. [Meme] OSI is Doing Just Fine

    So what if OSI is run by someone who raised money from Microsoft (to sell Microsoft a keynote slot in a copyleft event — the thing that Microsoft attacks through GitHub!) while funnelling the OSI's funds to a serial GPL violator?



  20. The OSI's Defunct Elections (Privacy Breach), Conflict of Interest (Nicholson), and Other Lingering Problems

    The above, together with an email from the OSI below, serves to show they’re re-running a bad election and — yet worse! — there appears to be a conflict of interest implicating the OSI’s sole member of staff!



  21. Links 30/7/2021: Audacity 3.0.3 and KD Chart 2.8.0

    Links for the day



  22. Links 29/7/2021: siduction 2021.2 and Xubuntu 21.10 Dev Update

    Links for the day



  23. GitHub is Racism

    Microsoft has the world's most racist code hosting repository; it wasn't like this when Microsoft took over as the racist policies were added to impress Donald Trump, who would later rig a procurement/tendering process to bail out Microsoft (10 billion dollars from the Pentagon, i.e. taxpayers)



  24. [Meme] António Lost His Power Over Patent Examiners

    Team Campinos at the EPO must be rather stressed at the moment; the people who do all the work can go on strike any time (or all the time, until/unless demands are met)



  25. European Patent Office is Going on Strike (or Strikes)

    The staff of the EPO is ready to strike like never before (dissatisfaction and outrage over 8 years of gross injustice, namely Battistelli's breach of fundamental rights, including the right to strike)



  26. Crying “Wolf!” About Systemd is Only Beneficial to IBM and Systemd Developers/Pushers

    Microsoft controls Systemd only to the extent that Systemd is controlled by GitHub, which is in turn controlled by Microsoft; But Systemd has long been on that proprietary platform (its developers don’t truly value software freedom) and this has long been a problem, even before Microsoft hijacked it for coercive power



  27. Links 29/7/2021: Mesa 21.2 RC3, FSF Responds to Microsoft's 'Hey Hi' Attack on Copyleft

    Links for the day



  28. IRC Proceedings: Wednesday, July 28, 2021

    IRC logs for Wednesday, July 28, 2021



  29. [Meme] No Crime Goes Unrewarded at the EPO

    It is more or less undeniable that from a legal and functional perspective the EPO is already defunct and is still perishing under a couple of Mafiosos whose sole interest is cover-up and grifting/plunder (of what’s left of the Office after almost 40 years of goodwill/reputation); the recent G 1/21 fiasco was just icing on the cake and the EU’s insistence on a patently unconstitutional UPC (more legal powers for chronic EPC violators) actually weakens unity in Europe (by discrediting the Union)



  30. [Meme] There's Always a Way (When Financial Results Are Not So Good...)

    Too many US ‘tech’ companies still lie to their investors. They choose financial engineering instead of real engineering.


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts