Microsoft Corp. said recent versions of its Windows operating system contain a "critical" security hole that an attacker could use to prevent some online transactions. In a security bulletin published late Wednesday, the software giant urged users of Windows 98, Millennium, NT 4.0, 2000 and XP to download a software patch that fixes the flaw.
A successful attacker wouldn't be able to steal personal information or take control of a victim's machine, said Lynn Terwoerds, security program manager at the Microsoft Security Response Center.
The flaw lies in a so-called ActiveX control used to prove that two parties exchanging information on the Internet are really who they claim to be.
An attacker would have to create and lure users to an infected Web page or send the page as an e-mail. A mail-based attack won't work if the recipient has the default security setting in Outlook Express 6 and Outlook 2002, or in Outlook 98 and 2000 if the user has installed a previous security update.
|