NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Vista Safe from Fresh XP Zero-Day

Also impacting Windows Server 2003

By Marius Oiaga, Technology News Editor

17th of October 2007, 07:56 GMT

Adjust text size:


Windows
Enlarge picture
It appears that the consistent efforts that Microsoft has poured into Windows Vista via the Secure Development Lifecycle are really paying off. In this context, the Redmond company's claim that Vista is the most secure Windows operating system on the market accurately reflects the superiority of Microsoft's latest platform. Illustrative in this sense is a new example of a zero-day vulnerability impacting Windows XP and Windows Server 2003.

Elia Florio, Symantec Security Response Engineer, revealed that a successful exploit leads to
local privilege escalation, but at this point, the security flaw was confirmed only on fully patched Windows XP SP2 and Windows Server 2003 SP1, but not on Windows Vista. Essentially, a user with local access to an XP or 2003 machine can gain higher privileges on system shell from a restricted account.

"At this time, we will not disclose the details of the vulnerability; however, we'll just say that the affected component is a driver that is shipped in many Windows installations by default. It is also included in the i386 folder. Under some circumstances, this driver can write into the kernel memory without proper restrictions", Florio explained.

Windows Zero Day
Enlarge picture
The main mitigating factor is the fact that the vulnerability is not remotely executable. A potential attacker would have to have physical access to the computer in order to run the exploit. Florio confirmed that Microsoft is already aware of the flaw, and that a patch is cooking.

"At the moment, it's still not clear how the driver is used by Windows because this file does not have the typical Microsoft file properties present in other Windows system files. Since this exploit was used in the wild, we are recommending system administrators be extremely careful at this time and restrict or disable access to unnecessary services for all accounts except for administrator-level users", Florio added.

TAGS:

Windows Vista | Windows XP | Windows Server 2003 | Symantec | vulnerabilityQ
Read by 983 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (3.0/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Announces the Availability of Vista SP1, XP SP3 and Windows Home Server

Upgraded IE7 Will Be Delivered as a High-Priority Automatic Update to All Windows Users

Internet Explorer 7 Is an Open Door for Attacks

Windows XP SP3 Beta Just Around the Corner?

Download Upgraded Internet Explorer 7 - Opened to All Pirated Copies of Windows!

Internet Explorer 7 in Windows Vista Is Hurt Bad

Supported Upgrade Paths to Windows Server 2008 Release Candidate 0

New Windows XP SP3 Beta Build 3205 Leaked to Torrent Trackers

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM