Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Microsoft > Security

September 20th, 2012, 11:42 GMT · By Bogdan Popa

Security Vulnerability in Windows 8 Can Lead to Malware Infection

SHARE:

Adjust text size:

EFI System Partition discovery
Enlarge picture
Security researchers at Italian firm ITSEC discovered that Windows 8 comes with a security flaw that could allow hackers to install malware on a vulnerable computer.

It’s all possible because of the Unified Extensible Firmware Interface (UEFI), an updated version of BIOS, which is available on Microsoft products since the debut of the 64-bit version of Windows 7.

In just a few words, the security researchers managed to develop a separate UEFI bootloader that can be installed on the vulnerable computers in order to replace the standard Windows 8 UEFI bootloader.

“Our bootloader hooked the UEFI disk I/O routines and it intercepted the loading of the Windows 8 kernel, thus our bootkit tampered the kernel by disabling the security features used by Windows to prevent the loading of unsigned drivers,” Marco Giuliani, director of ITSEC, was quoted as saying by The Register.

What’s more, the same exploit could be used on some other platforms too, including OS X and Linux distributions, which is a bit worrying since both are getting more popular these days. OS X already uses UEFI since 2010 and the vulnerability can be exploited in a similar way.

Talking about Windows 8’s security level, Gerry Egan, Symantec senior director, product management, said that Microsoft doesn’t seem to spend too much time working on this chapter, emphasizing that a third-party security app will most likely be needed.

“It's partially true that Windows 8 is more secure,” Egan explained. “But underneath is a traditional Windows-Intel desktop, which is backward compatible with both the good code and the bad.”

The whole analysis made by ITSEC is included in a very detailed blog post that can be read here.


3,195 hits · 3 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Microsoft Plans to Move All Windows XP Users to Windows 8

Microsoft Updates IE9 Critical Flaw Workaround, Still No Fix

Windows 8’s Outlook 2013 Boasts a Tablet-Adaptable Experience

Windows 8 Security Is Not Good – Symantec

Windows 8 Is a Disaster, Says Microsoft’s Bing

READER COMMENTS:


Comment #1 by: herbie643 on 23 Sep 2012, 19:43 UTC reply to this comment

Where there is a will there is a way.


Comment #2 by: pbug56 on 23 Sep 2012, 20:09 UTC reply to this comment

If you are stupid enough to go for Windoze 8, then don't worry about the bugs, etc.

Comment #2.1 by: blinkdt on 14 Jan 2013, 18:56 GMT

Sure, I'd much rather use a malware prone OS like OSx that doesn't include any protection at all. And I have no idea if I am infected. It's cool to be a tool, eh?

P.S. Win8 is bullet proof for the average user, with SmartScreen filter and Defender getting the job done in fine fashion.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM