Windows XP SP2 said at risk from heap overflow

InternetNews | at | by Mike

Microsoft said it is is investigating a report from Alexander Anisimov of the Russian security firm Positive Technologies that details how to bypass Windows XP SP2 heap protection to create an attack vector for a buffer overflow attack.

According to Positive Technologies' security scanning product MaxPatrol, it initially notified Microsoft of the bypass on Dec. 21, 2004, and sent proof of concept code to the company on Dec. 22nd. MaxPatrol also indicated that Microsoft provided an initial response on the same day, though at this point it does not appear as though a fix or patch has been issued.