New flaw found in XP and Windows 2000
Danish researchers have discovered a new vulnerability affecting two of Microsoft’s older operating systems.


A new flaw discovered in two of Microsoft's operating systems is leaving machines vulnerable to hack attacks.
The "moderately critical" issue was discovered by Danish security research firm Secunia in Windows 2000 and XP, although the company indicated it could affect other versions too.
In a security advisory, Secunia said: "The vulnerability is caused due to a boundary error in the "UpdateFrameTitleForDocument()" function of the CFrameWnd class in mfc42.dll. This can be exploited to cause a stack-based buffer overflow by passing an overly long title string argument to the affected function."
"Successful exploitation may allow execution of arbitrary code."
Secunia has claimed the solution to the bug would be to "restrict access to applications allowing user-controlled input to be passed to the vulnerable function."
Microsoft acknowledged the concerns via its Microsoft Security Response Twitter feed and said: "We are investigating reports of a vulnerability in mfc42.dll affecting Windows 2000 and XP. Will update when we have more information."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Jennifer Scott is a former freelance journalist and currently political reporter for Sky News. She has a varied writing history, having started her career at Dennis Publishing, working in various roles across its business technology titles, including ITPro. Jennifer has specialised in a number of areas over the years and has produced a wealth of content for ITPro, focusing largely on data storage, networking, cloud computing, and telecommunications.
Most recently Jennifer has turned her skills to the political sphere and broadcast journalism, where she has worked for the BBC as a political reporter, before moving to Sky News.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Tiny11 review: Windows 11 with only 2GB of RAM
Review A version of Windows 11 for older machines that don't meet the full requirements
By Nik Rawlinson Published
-
Red Hat Enterprise Linux becomes foundational operating system for Cohesity Data Cloud
News New strategic partnership between Red Hat and Cohesity aims to drive innovation in the data security and management space
By Daniel Todd Published
-
Ubuntu shifts to four-week update cycle
News Critical fixes will also come every two weeks, mitigating the issues involved with releasing prompt patches on the old three-week cadence
By Richard Speed Published
-
AlmaLinux follows Oracle in ditching RHEL compatibility
News Application binary compatibility is now the aim with 1:1 now dropped
By Richard Speed Published
-
How big is the Windows 10 cliff-edge?
ITPro Network With some comparing the upcoming Windows 10 end of life to Windows XP, we ask members of the ITPro Network for their insight
By Jane McCallion Published
-
Everything you need to know about the latest Windows 11 updates - from bug fixes to brand-new features
News Two new cumulative updates are on the way and will be installed automatically on Windows 10 and Windows 11 machines
By Rory Bathgate Published
-
How to download a Windows 11 ISO file and perform a clean install
Tutorial Use a Windows 11 ISO to install the operating system afresh
By John Loeppky Published
-
We could all benefit from better Windows and macOS accessibility features
Opinion Today’s accessibility features can help you work through a nasty injury, but there’s still plenty of room for improvement
By Barry Collins Published