Don't Let Your Windows Get "Shattered"
Saturday July 12, 2003
Security researchers discovered a class of security flaws that use the Windows messaging system to request privileged applications to run malicious code. The original discoverer of this type of attack dubbed it "shatter." When informed of the flaw last fall Microsoft insisted that because the attacker would need physical access to the PC it was not a flaw at all. Eventually they patched it anyway. Now, researchers are pointing out that Microsoft only patched the instance of the flaw for one specific process, while leaving the root vulnerability and other applications open to attack. For more information you can read this News.com article.
