NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Merry Vista Vulnerability!

Microsoft confirms Vista zero-Day flaw

By Marius Oiaga, Technology News Editor

26th of December 2006, 08:34 GMT

Adjust text size:


On December 15, 2006, Proof-of-Concept code was published for a zero-day Windows Client/Server Runtime Server Subsystem (CSRSS) vulnerability. As early as December 22, the Redmond
Company was informed of the issue and has began working on a patch. You can read additional information as well as limited technical details related to this vulnerability here.

"Aside from discussing the holidays, the reason I am dropping in on the blog is that right now we are closely monitoring developments related to a public posting of proof of concept code targeting an issue with the Client Server Run-Time Subsystem. The PoC reportedly allows for local elevation of privilege on Windows 2000 SP4, Windows Server 2003 SP1, Windows XP SP1, Windows XP SP2 and Windows Vista operating systems," stated Mike Reavey, security program manager for Microsoft.

According to Microsoft's perspective based on a preliminary analysis of the zero-day vulnerability, a successful exploit via the CSRSS flaw depends on the attacker having already authenticated access to the target system. Although the vulnerability is not limited to Windows Vista, the security community has labeled it as a minor threat.

"Currently we have not observed any public exploitation or attack activity regarding this issue. While I know this is a vulnerability that impacts Windows Vista I still have every confidence that Windows Vista is our most secure platform to date. As always, we here at the MSRC encourage everyone to enable a firewall, apply all security updates and install anti-virus and anti-spyware software," added Reavey.

In this context, Microsoft informed that the holiday season will have no impact on the company's work to produce a security update for the CSRSS vulnerability. Considering that the Redmond Company has not even detected limited exploit attempts related to the flaw, a patch addressing the flaw will most likely be released on January 9, 2007.

"Regardless of it being the holiday season the MSRC will be monitoring overall threat conditions for this and any other issue reported to us. If we do see anything that we believe puts Microsoft customers at risk, or significant new developments, we will update everyone through our standard mechanisms," concluded Reavey.
Read by 1,327 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.2/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


133 Critical and Important Microsoft Vulnerabilities

Internet Explorer 7 - Zero Vulnerabilities

The Third Exploit for Microsoft Word Vulnerability

Seven December 2006 Security Bulletins

Inspect OS and Software Security

Details on Three Unpatched MS Word Vulnerabilities

Internet Explorer 7 Down - Firefox 2.0 Up

The Coordinates of an MS Word Attack

Free IE6 VPC + Windows XP SP2 = a Microsoft Success

New Worm - Old Vulnerabilities

PoC Published for Internet Explorer 7 Vulnerability

IE7 Speaks Chinese and Hebrew

Second Word Zero-Day Vulnerability in a Week

Upgrade to IE7 Optimized for Google

No December Security Updates for Office on Mac

Microsoft SQL Server Is the Heart of Wireless Development

The First Internet Explorer 7 Vulnerability

Windows Vista Vulnerabilities

Firefox 2.0 Continues to Grow in the Detriment of IE7

The First Update for Internet Explorer 7

Mozilla Unveils Firefox 3.0 Gran Paradiso

Install Visual Studio 2005 SP1 on Windows Vista

Microsoft's "Very Limited, Targeted Attacks"

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM