Microsoft yanks patch causing XP PCs to crash

Analysis
Feb 12, 20103 mins

Microsoft removes troublesome patch for consumers, but not for enterprises using WSUS or SMS

Hundreds of users posted messages on a Microsoft support forum complaining that Patch Tuesday’s updates were crashing their XP computers. Indeed, a couple of readers wrote to Microsoft Subnet about the problem, too. Microsoft responded on Thursday by removing the offending patch from its automatic download for consumers. However it did not remove the patch from its enterprise patch management systems.

The troublesome patch was narrowed down to MS10-015. Microsoft didn’t step up to take full blame for the problem — saying that the issue could be caused by third-party software. Indeed, some independent security researchers are seconding that opinion, saying a rootkit appears to be the cause. Patrick W. Barnes, an Amarillo, Texas-based computer expert who is credted with discovering the infection, posted instructions on how to repair the atapi.sys file. (Warning: his blog appeared to be offline on Friday morning, presumably from the traffic caused by people wanting those instructions.)

Jerry Bryant, a senior manager with the Microsoft Security Response Center (MSRC), said in a blog post that the security team is still investigating. Until then, Bryant urged users to install the other patches, and to implement an automated workaround that disables the vulnerable NT Virtual DOS Mode (NTVDM) subsystem.

MS10-015 fixed a pair of 17-year-old kernel bugs in 32-bit versions of Windows. The holes became public three weeks ago when a Google engineer published proof-of-concept attack code, reports Computerworld.

While consumers won’t find the patch automatically pushed to them, it has not been removed from enterprise auto-patching systems. Says Bryant,” those using enterprise deployment systems such as SMS or WSUS will still see and be able to deploy these packages.”

Microsoft says that XP users who are experiencing these issues can get by either going to https://consumersecuritysupport.microsoft.com or by calling 1-866-PCSafety (1-866-727-2338). International customers can find local support contact numbers here: https://support.microsoft.com/common/international.aspx.

Like this post? Check out these others.

  • Microsoft fixes 26 security holes, warns on unpatched multi-vendor SSL vulnerability
  • Startup Huddle wins Microsoft’s SharePoint 2010 contest
  • Microsoft gags ex-CFO Chris Liddel and pays him $1.9M
  • Microsoft posts record-breaking Q2, thanks to consumers, Windows 7
  • 7 big IT orgs that showed Microsoft the door
  • Most business will adopt Windows 7 by 2011, but prefer Google’s cloud
  • Windows 7 Remote Admin Tools: Controls Windows Server 2008 from your Windows 7 desktop
  • Secrets of Exchange Server 2010
Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.) All Microsoft Subnet bloggers on Twitter Julie Bort on Twitter

Follow

Follow