Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

EDITORIALS

The Quasi Immaculate Windows Vista

- But immaculate nonetheless

By: Marius Oiaga, Technology News Editor

Windows Vista has stepped into this world and on store shelves with a quasi immaculate record. Quasi immaculate due to the fact that two vulnerabilities affect the operating system. One[ADMRK=1] is an issue with the Client Server Run-Time Subsystem and the other affects the Windows vista Speech Recognition feature. And although the problems are real, the severity level that can be attributed to either one does not expose the user or the integrity to its data to critical attacks.

Microsoft
Windows MessageBox Vulnerability has been around since mid-December 2006. On the background of the limited availability of the operating system, this vulnerability has failed to generate any real issues. McAfee ranked it as a medium threat and Microsoft did not rush to patch it. Even after the commercial availability of Vista, this issue is still valid. Still valid but without real impact on Vista users. In the worst case scenario, the MessageBox vulnerability only allows for DoS or local privilege escalation.

And Windows Vista has managed to avoid the VLM vulnerability due to the fact that the operating system is compiled with the C++ compiler available in Visual Studio 2005 that automatically detects integer overflows at runtime, yet another vulnerability has moved to the center stage of the Speech Recognition features.

The Windows Vista Speech Recognition Fatal Vulnerability should receive the "joke" security ranking. Microsoft itself revealed that the possibility of such an exploit is only technical. The reality is quite different. Because for a remote attacker to take control of Vista via speech recognition is an absurd scenario.

Users are as exposed to the Vista Speech recognition vulnerability only in theory. The fact that attacker could use the speech recognition capability of Vista to take control over the system is highly unlikely. A potential attacker would be limited to voicing commands such as "copy", "delete" or "shutdown." Windows Vista, in its default configuration does not allow for User Account Control to be managed via voice commands, and therefore the limitations make this vulnerability a non-issue. Not to mention, that you would actually be able to hear the exploit!

And as this wasn't enough, the Windows Vista Speech Recognition requires a certain clarity of dictation. Also, the speech profiles entered into the operating system have to match those of the attacker. Furthermore, microphone and speaker placement is another variable that constitutes a barrier to this exploit.

So, unless you place your microphone next to the high-definition speakers, and train your speech patterns to the voice of the attacker, also allowing for UAC modifications via voice commands, you should be OK.

Quasi immaculate, but immaculate nonetheless.


<span style='color:orangered'><b>MORE RELATED ARTICLES: </b></span>
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:

10th February 2007, 10:12 GMT | Copyright (c) 2007 Softpedia | Contact:
Read by 2,753 user(s) | Rating: | 11 vote(s) so far | Cast your vote:
The Quasi Immaculate Windows Vista - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT The Quasi Immaculate Windows Vista

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive