Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

April 4th, 2007, 11:13 GMT · By

Symantec Exposes Windows Vista

SHARE:

Adjust text size:



Enlarge picture
Cupertino-based security company Symantec has taken another swing at Windows Vista designe to bring into focus Microsoft's inaccurate Teredo documentation and other common vulnerabilities
and exposures in the operating system. At the basis of Symantec's initiative are no less than nine new CVEs issued just last week under the CVE project. Symantec claims that all the CVEs have been requested by a third-party but that they are all based on its Windows Vista Network Attack Surface Analysis report published on March 7, 2007.

"We don't feel that most of the issues are especially significant. Microsoft reviewed the paper prior to its public release and Symantec would participate in any warranted responsible disclosure for vulnerabilities," stated Jim Hoagland, with the Symantec Security response.

Adopting a mild tone of voice, Hoagland revealed that just CVE-2007-1535 can be considered an important issue and even make it as a half decent vulnerability Symantec has focused intensively on, the new network protocol stack in Windows Vista claiming that the technology is immature and inherently vulnerable. "Teredo is an IPv6 transition technology that provides address assignment and host-to-host automatic tunneling for unicast IPv6 traffic when IPv6/IPv4 hosts are located behind one or multiple IPv4 network address translators (NATs)," according to a Microsoft description.

And CVE-2007-1535 focuses directly on Teredo. According to Symantec, the technology has a tendency to become active despite Microsoft's own documentation. "The described issue is that Teredo (an IPv4 to IPv6 transition technology that works through NATs) becomes qualified (active) even in situations where the Microsoft documentation says it should not be," Hoagland revealed.

According to Microsoft, the Teredo component is enabled in Windows Vista but also inactive by default. Symantec disputes this and revealed that Teredo automatically became active in several common scenarios.
FILED UNDER:
Windows Vista
Teredo

TELL US WHAT YOU THINK:

1,530 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


When Windows .ani Files Attack

Attackers Can Potentially Run Malicious Applications on Windows Vista

Windows Vista, 90-Day Vulnerability Report

A Windows Vista Zero-Day Is Pure Gold

Windows Vista Is Hard As a Rock

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM