NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Five-Year-Old Windows Design Flaw Comes Back to Haunt Vista

Via Windows Proxy Autodiscovery

By Marius Oiaga, Technology News Editor

27th of November 2007, 10:20 GMT

Adjust text size:



Enlarge picture
Windows Vista, Microsoft's latest operating system, has been continually applauded as an apex of security and an epitome of user protection when it comes down to the Windows platforms available on the market. Yet Vista is far from being bulletproof despite the additional security mitigations built into the product from User Account Control to Address Space Layout Randomization. And although Vista is the first product to come out of the Security Development Lifecycle, as a new software building methodology and process designed to tone down the
severity and reduce the volume of vulnerabilities, Microsoft still managed to miss some issues.

Case in point, a five-year-old design flaw, already discovered and patched by the Redmond company, has come back to haunt Vista, according to New Zealand hacker Beau Butler who presented the vulnerability at the Kiwicon hacker conference in Wellington. Although the security hole has been reported not to affect the U.S. version of Vista, users around the world running the operating system are vulnerable to severe attacks. Butler also revealed that Vista is by no means the sole operating system vulnerable, with the flaw impacting all versions of Windows.

The vulnerability is related to the Microsoft WPAD functionality, and involves problems with Windows Proxy Autodiscovery. Butler stated that because of the vulnerability, Windows proxy auto-configuration requests are frequently sent out on the Internet. The flaw essentially allows an attacker to serve false proxy information to vulnerable machines, and in this manner to take over thousands if not million of computers simultaneously.

Microsoft confirmed both the vulnerability and its severity, and added that a patch is in the works. However, Microsoft's general manager of product security, George Stathakopoulos, informed that not all Windows machines are vulnerable, and that the configuration of the operating system has a great deal to do with putting its user at risk.

TAGS:

Windows Vista | Windows | vulnerability
Read by 1,563 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.2/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


There Is Life Beyond Vista - Windows Users Turn to Mac OS X and Linux

Download the Windows Vista Experience

Microsoft: We Are Selling Windows Vista! Really Now! We Are!

Forget about Vista - Onward to Future Versions of Windows...

The Tropic of Windows Vista - If You Are Not on Microsoft's Vista Map in Virtual Earth

Microsoft Doesn't Let Users Touch the Immaculate Windows Vista

Windows Vista Hardware Assessment

Windows Is 22 Years Old

Windows Vista SP1 Release Candidate Just Around the Corner

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM