funsec mailing list archives

Microsoft Updates Windows Without Users' Consent


From: "Paul Ferguson" <fergdawg () netzero net>
Date: Thu, 13 Sep 2007 00:55:21 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Via Windows Secrets.

[snip]

In recent days, Windows Update (WU) started altering files on users'
systems without displaying any dialog box to request permission. The only
files that have been reportedly altered to date are nine small executables
on XP and nine on Vista that are used by WU itself. Microsoft is patching
these files silently, even if auto-updates have been disabled on a
particular PC.

It's surprising that these files can be changed without the user's
knowledge. The Automatic Updates dialog box in the Control Panel can be set
to prevent updates from being installed automatically. However, with
Microsoft's latest stealth move, updates to the WU executables seem to be
installed regardless of the settings — without notifying users.

[snip]

More:
http://windowssecrets.com/comp/070913/#story1

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)

wj8DBQFG6Ipzq1pz9mNUZTMRAuveAJ9rGuDj7ETcv6Brw82e3xU50a20LQCePulp
8MWQwumWh9HA7rMDm5KIMaA=
=FoKQ
-----END PGP SIGNATURE-----



--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: