Windows XP Service Pack 2 has a flaw that gives users a false sense of security - quite literally. One report describes the security hole as a 'crater'. The vulnerability lies in the web systems management interface (WBEM), which allows downloadable code to spoof firewall status information.
It's a convoluted exploit, but in theory, a rogue application could wait until the firewall is down and then generate false system information indicating that the firewall is in fact up and working. That's because the WMI database - Microsoft's implementation of WBEM - is set to read/write, not read-only, reports eWeek. The magazine's labs used a simple script to generate false firewall status information.
Copyright©2004 Gold-Horizons