The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Windows Security
Average Rating:
Rate this article:  
'Black Screen' Overhyped and Not Microsoft's Fault
By Carl Weinschenk
December 3, 2009 2:05PM

Bookmark and Share
British security firm Prevx has conceded that Microsoft security patches were not the cause of a Windows issue labeled the Black Screen of Death. Prevx had said the problem was widespread and might compromise Windows XP, Vista and Windows 7. Security officers and Microsoft called the Black Screen problem overhyped and relatively minor.
 


After creating great distress in security circles, an issue with Microsoft Windows has proven relatively minor. The problem, labeled the Black Screen of Death, was initially thought to be widespread. Indeed, British security firm Prevx posted a series of blog items suggesting that several million computers using Windows XP, Vista and Windows 7 could be compromised. The company said the problem often is associated with two Windows security patches, KB915597 and KB976098.

Prevx has since backtracked, though a bit obliquely. In a posting Wednesday, the firm said the problem is still widespread and its free tool to fix the issue had been downloaded more than 50,000 times.

The company denied that it made concrete claims. "As you will see, at no time have we categorically stated that these patches are the cause of the Black Screen problem," it said. "We shared our initial findings around the two patches with Microsoft, conducted further tests, and have confirmed that these specific updates are not the root cause."

Microsoft: Updates Not to Blame

Mike Murray, chief information security officer for Foreground Security, said the entire affair is a non-story. "I am absolutely amazed this became the story it became," he said. "They say the number [of infected machines] is 50,000. I say it's more like 10 percent of that. I hate it when security companies throw out all this hyperbole. I have known large organizations ... that are using Windows 7 in large parts of their [companies], and I have not heard one report from any of my clients on this problem."

Microsoft also called the problem overhyped, if not nonexistent. "Microsoft has investigated reports that its November security updates made changes to permissions in the registry that that are resulting in system issues for some customers," said a statement attributed to Christopher Budd, Microsoft's security response communications lead.

"The company has found those reports to be inaccurate and our comprehensive investigation has shown that none of the recently released updates are related to the behavior described in the reports," the statement says. "While we were not contacted by the organization who originally made these reports, we have proactively contacted them with our findings."

The statement also says that Microsoft's support organization doesn't see any issues. "The claims also do not match any known issues that have been documented in the security bulletins or KB articles," it said.

Roger Halbheer, chief security adviser for Microsoft EMEA, was not amused. His post at TechNet Blogs is critical of Prevx and, by implication, the many sites that uncritically carried the initial and inaccurate reports.

Be Careful Who You Listen To

Halbheer concludes users should be careful who they listen to. "[Y]ou should now make your risk assessment and decide which source you want to trust. For me, the ultimate source for information you should build your assessment on is neither Twitter nor your brother's sister-in-law's father's brother (unless he works for Microsoft's security) but our web site."

Murray agrees that Prevx's approach was wrong. "I would hope they would work with the vendors and be a little more responsible in the way they run around talking about this stuff," he said. "I almost laughed when they said that they feel bad about embarrassing Microsoft. They got themselves all over the news by embarrassing Microsoft."
 

Tell Us What You Think
Comment:

Name:



Advertisement


 Windows Security
1.   Fix Your Internet Explorer Annoyances
2.   Patch Fixes SMB Danger from Within
3.   August Patch Flood Will Keep IT Busy
4.   Emergency MS Patch Fixes Shortcuts
5.   Windows 7: Secrets of the Start Menu


advertisement
Fix Your Internet Explorer AnnoyancesFix Your Internet Explorer Annoyances
Love it or hate it, you probably use it.
Average Rating:
Patch Fixes SMB Danger from WithinPatch Fixes SMB Danger from Within
Outside worker could bring in attack.
Average Rating:
August Patch Flood Will Keep IT BusyAugust Patch Flood Will Keep IT Busy
Traditional defenses may be obsolete.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.