Follow Us

Windows XP zero day flaw gets work around

Microsoft: Delete the HCP key to disable help centre protocol

Microsoft has offered a workaround to Windows XP users affected after a flaw in the operating system was exploited.

Since Google engineer Tavis Ormandy released details of the zero-day flaw last month, cyber criminals have dramatically ramped up online attacks that target the bug. Microsoft revealed it has now logged more than 10,000 attacks.

"At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged," Microsoft said in a blog posting.

The flaw lies in the Windows Help and Support Center software that comes with Windows XP.

Ormandy was criticised by some in the security community for not giving Microsoft more time to patch the flaw, which he disclosed to the software vendor on June 5. He released details of the bug five days later, apparently after failing to convince Microsoft to fix the issue within 60 days.

Microsoft said in an advisory it is investigating the issue, and it may issue an out-of-schedule patch for the problem.

"Microsoft is also aware of limited, targeted active attacks that use this exploit code. Based on the samples analyzed, Windows Server 2003 systems are not currently at risk from these attacks. Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary," the advisor says.

However, until then, it is advising those with affected PCs to use a one-click Fix-It tool to disable the Help Centre Protocols.

Alternatively, Windows XP users can disable HCP manually. Click the Start menu, followed by Run. Type regedit and press ok. Highlight the HCP key after expanding the HKEY_CLASSES_ROOT folder. Then right click on the HCP key and select Delete.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Business continuity and disaster recovery for SMBs

Business continuity (BC) and disaster recovery (DR) are major issues for all businesses, with...

Download Whitepaper

How to get your business ready for the 2012 Olympics

IT Manager: "I'm working on contingency plans to ensure that we can keep the business running...

Download Whitepaper

10 things you have to do today to protect your business in 2012

The next twelve months will be like a fair ground ride: rotation, uncertainty and mild...

Download Whitepaper

Data protection strategies in the age of the iPad

In today’s target-rich environment, CISOs must focus on defending the content of files and...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *