No Patch for Critical Win98 Flaw

執筆者
Ryan Naraine
Ryan Naraine
Published: Jun 9, 2006
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

One month before the expiration of support for Windows 98, Microsoft says its simply “not feasible” to create patches for a critical flaw affecting the 8-year-old operating system.

The vulnerability, patched for other Windows operating systems in the MS06-015 bulletin, exists in the way Windows Explorer handles COM (Component Object Model) objects but, although it puts Windows 98 users at risk of code execution attacks, Microsoft warned that a fix would not be made available.

“After extensive investigation, weve found that its not feasible to make the extensive changes necessary to Windows Explorer on these older versions of Windows to eliminate the vulnerability,” said Christopher Budd, a program manager in the MSRC (Microsoft Security Response Center).

Public and technical support for Windows 98, Windows 98 SE (Second Edition), and Windows ME (Millennium Edition) formally ends on July 12, the scheduled day for security patches in July.

In a post on the MSRC blog, Budd said Microsoft has made “significant enhancements to the underlying architecture of Windows Explorer” since the development on Windows 2000, meaning that the architecture on older operating systems versions is “much less robust.”

“Due to these fundamental differences, these changes would require reengineering a significant amount of a critical core component of the operating system. After such a reengineering effort, there would be no assurance that applications designed to run on these platforms would continue to operate on the updated system,” Budd said.

/zimages/5/28571.gifClick hereto read more about Microsofts recommendations for dealing with an exploitable flaw in Microsoft Word.

Microsofts recommendation is for Windows 98 customers to protect those systems by placing them behind a perimeter firewall that filters traffic on TCP Port 139. This will block attacks attempting to exploit the Windows Explorer flaw

With security support ending, the company is again urging users to upgrade to a newer, more secure version, such as Windows XP Service Pack 2, as soon as possible.

Support for Windows XP SP1 ends on October 10, 2006.

Advertisement

The latest information comes as Microsoft is preparing to release a dozen bulletins to cover a wide range of flaws affecting Windows, Microsoft Office and Microsoft Exchange. A patch for the Internet Explorer browser is also on tap.

One of the Microsoft Office patches will cover a zero-day vulnerability in Microsoft Word that has already been exploited in targeted attacks.

/zimages/5/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。