Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

October 17th, 2007, 07:56 GMT · By

Vista Safe from Fresh XP Zero-Day

SHARE:

Adjust text size:


Windows
Enlarge picture
It appears that the consistent efforts that Microsoft has poured into Windows Vista via the Secure Development Lifecycle are really paying off. In this context, the Redmond company's claim that Vista is the most secure Windows operating system on the market accurately reflects the superiority of Microsoft's latest platform. Illustrative in this sense is a new example of a zero-day vulnerability impacting Windows XP and Windows Server 2003.

Elia Florio, Symantec Security Response Engineer, revealed that a successful exploit leads to
local privilege escalation, but at this point, the security flaw was confirmed only on fully patched Windows XP SP2 and Windows Server 2003 SP1, but not on Windows Vista. Essentially, a user with local access to an XP or 2003 machine can gain higher privileges on system shell from a restricted account.

"At this time, we will not disclose the details of the vulnerability; however, we'll just say that the affected component is a driver that is shipped in many Windows installations by default. It is also included in the i386 folder. Under some circumstances, this driver can write into the kernel memory without proper restrictions", Florio explained.

Windows Zero Day
Enlarge picture
The main mitigating factor is the fact that the vulnerability is not remotely executable. A potential attacker would have to have physical access to the computer in order to run the exploit. Florio confirmed that Microsoft is already aware of the flaw, and that a patch is cooking.

"At the moment, it's still not clear how the driver is used by Windows because this file does not have the typical Microsoft file properties present in other Windows system files. Since this exploit was used in the wild, we are recommending system administrators be extremely careful at this time and restrict or disable access to unnecessary services for all accounts except for administrator-level users", Florio added.

TELL US WHAT YOU THINK:

1,319 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Announces the Availability of Vista SP1, XP SP3 and Windows Home Server

Upgraded IE7 Will Be Delivered as a High-Priority Automatic Update to All Windows Users

Internet Explorer 7 Is an Open Door for Attacks

Windows XP SP3 Beta Just Around the Corner?

Download Upgraded Internet Explorer 7 - Opened to All Pirated Copies of Windows!

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM