Go Back   Windows Vista Forum | Vista Babble > Windows Vista > Vista News

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 02-28-2007, 08:38 PM
Snuffy's Avatar
Elite Members
 
Join Date: Nov 2006
Location: S.W. Kansas
Posts: 2,841
Snuffy is on a distinguished road
Send a message via MSN to Snuffy
Smile Vista Security is Vulnerable


New Vulnerability Found In Windows Vista


section: windows, for your questions: IT forum, 28.2.2007

A security vendor based in Aliso Viejo, California has found a vulnerability with a 'medium' security rating in Microsoft's Windows Vista.
The flaw, which eEye first reported as an Upcoming Advisory, is one of the first to be found in the brand new operating system. Earlier this month, Microsoft patched a flaw in Windows Defender, which is a built-in spyware and security component in different applications, including Windows XP and Vista. Maiffret points out that this new flaw is in the Vista operating system itself, not in a component that has been used in various programs.

eEye researches found the vulnerability on Jan. 9 and reported it to Microsoft on Jan. 19. Vista wasn't released for retail until the end of January.

The vulnerability enables regular users to grab more power on the system.

"A main security feature added to Vista is that regular users have a lower level of privileges," says Maiffret. "They have fewer privileges in Vista than they did in Windows XP. When regular users are running the operating system, they have regular user-level access, but with this vulnerability, you can elevate yourself to system-level access. Any normal user can do anything they want to the system."

Maiffret says they gave it a "medium" security rating because it doesn't enable a remote user to control the system. But he also says it wouldn't take much to elevate it.

"If it was coupled with a virus or a different remote vulnerability, it would be a lot more serious," he adds. "Viruses are very prevalent and there are plenty of other vulnerabilities you can couple it with. In a real world context, it's high because there are a lot of other things you can couple it with to make it pretty nasty. On its own, though, it's only medium."

A spokesman with Microsoft said researchers still are investigating the vulnerability.

__________________
The only Stupid Question is the one you failed to Ask!
Beta Tester since Pre Win 95.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Sponsored Links
  #2  
Old 03-02-2007, 03:19 AM
Snuffy's Avatar
Elite Members
 
Join Date: Nov 2006
Location: S.W. Kansas
Posts: 2,841
Snuffy is on a distinguished road
Send a message via MSN to Snuffy
Thumbs down Symantec says Vista suksSymantec: Out of the Box, Vista Prone to Legacy Threats

Symantec Security Response has spent months throwing every hack but the kitchen sink at Microsoft's Vista operating system, and on Feb. 28 it released a series of papers that showed just how bloodied or victorious Vista remained.

The result: "There are existing codes that can survive Vista without being modified— [certain] keyloggers, worms, Trojans, and spyware are able to survive," said Symantec Research Scientist Ollie Whitehouse in an interview with eWEEK.

The current threat level of the Vista security-resistant malware is "relatively low," Whitehouse said, but he said that out of box, Vista already has several legacy threats. "It won't take much for [those] to evolve," he said.

This is in spite of Microsoft's years of work and investments in new security technologies, which Symantec predicted will result in "fewer instances of widespread worms that target core Windows operating system vulnerabilities," researchers wrote in one report, "Microsoft Windows Vista and Security."

The papers form one of the latest swipes at Vista security taken by security vendors including Symantec, who suddenly found Microsoft to be a large and fearsome competitor when the software giant leapt into the security software game. Microsoft had not yet responded to a request for feedback on the papers at the time this story was posted, although a Symantec spokesperson said that Symantec has briefed Microsoft on the material.

read the rest: http://www.eweek.com/article2/0,1895,2099072,00.asp
__________________
The only Stupid Question is the one you failed to Ask!
Beta Tester since Pre Win 95.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 07:33 AM.



Page generated in 0.13533 seconds with 10 queries

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23