Microsoft patches first critical bug in Windows 7 beta

Three kernel vulnerabilities also affect newest OS

Microsoft patched the first critical vulnerability in Windows 7 Tuesday as it rolled out an update that fixes three flaws in the new operating system's kernel.

The MS09-006 update, which researchers tagged as the most serious of the three issued Tuesday and the one to patch first, includes a critical bug in the kernel's processing of input delivered by the graphical device interface (GDI), the core graphics rendering component of Windows.

According to Microsoft, the public beta of Windows 7, as well as previews of other editions of the OS, contain the three flaws fixed by MS09-006. "These vulnerabilities were reported after the release of Windows Server 2008 Service Pack 2 Beta, Windows Vista Service Pack 2 Beta, and Windows 7 Beta," Microsoft said in the accompanying bulletin. "Customers running these platforms are encouraged to download and apply the update to their systems."

All supported versions of Windows, ranging from Windows 2000 and XP to Vista and Server 2008, require patching. "It's in all versions of Windows; it's deep in the kernel and in GDI," Wolfgang Kandek, chief technology officer at security company Qualys, said in an interview Tuesday.

Attackers could use malformed WMF (Windows Metafile) or EMF (Enhanced Metafile) images to exploit the bug in Windows 7, just as they could in other editions. Microsoft said the malicious images could be fed to users via e-mail, placed on Web sites or added to other documents. Simply viewing the images would trigger the vulnerability.

Computerworld has confirmed that machines running the public preview of Windows 7, which Microsoft offered for a month, from January 10 to February 12, are offered the MS09-006 security update.

This is not the first time that Microsoft has patched Windows 7. Just days after it delivered the beta, it fixed a flaw that shaved several seconds of audio from MP3 files. At the time, a Microsoft spokesman said that the only Windows 7 bugs the company would patch using Windows Update were those tagged "critical."

"This tells us that Windows 7 is not only a cousin of Vista, but also a cousin of Windows 2000," said Kandek Wednesday, referring to the fact that even the ancient Windows 2000 contains the kernel vulnerabilities. "Certain things in the kernel have obviously not changed in Windows 7."

The Windows 7 security update can also be downloaded manually from Microsoft's site in versions for the 32-bit and 64-bit editions of the operating system.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Windows 7

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Gregg Keizer

Gregg Keizer

Computerworld
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?