NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Vista Speech Recognition Vulnerability - Video Demonstration

Computer, Initiate Self Destruct Sequence!

By Marius Oiaga, Technology News Editor

17th of February 2007, 10:49 GMT

Adjust text size:


Symantec has decided to put the Windows Vista Speech Recognition vulnerability to the test. Via Speech Recognition, Vista users have the possibility to dictate arbitrary text instead of
using the keyboard and to perform a selection of pre-defined tasks. Because Vista is designed to operate vocal commands such as "delete", "press the escape key," "press Ctrl and A" etc., the remote possibility exists that the operating system could be subverted via malicious audio clips.

James O'Connor, Symantec Security Response Engineer has tested the Vista Speech recognition and you are able to see the result first hand in the video embedded as the bottom. The scenario Symantec has proposed involves a user surfing the Internet with Speech Recognition enabled. If the user manages to find his way to a malformed website that contains a malicious audio clip playing in the background, theoretically, Vista could receive instructions through Speech Recognition.

"So is this feasible? We decided to test it out, by recording a short audio clip that deletes all the files in the "Pictures" folder. I then added the clip to a Web page and proceeded to visit that page. Sure enough, as soon as I opened the page, the computer began executing the commands, and soon all the files were deleted from the "Pictures" folder," explained O'Connor.

Symantec advised Vista users to switch off Speech Recognition while viewing the video. But for an "attack" to take place, there are additional aspects that need to go hand in hand, besides visiting the malicious site. Speech Recognition must be enabled, the speaker's volume must be turned up, and the microphone must be positioned adequately. And last but not least, the user must be deaf or simply allow the voice "attack" to carry on.

"Also, Speech Recognition cannot be used to bypass UAC (User Account Control), so unless UAC is disabled, a malicious clip can't make any critical changes to the system. In the scheme of things, this is probably not the most severe security risk ever to grace our presence, but it is an interesting new vector of attack that few people would have considered previously," O'Connor added.

Read by 2,133 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.1/5) 10 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Patches Critical Vulnerability In Windows Vista

The Quasi Immaculate Windows Vista

Windows Vista UAC Implementation Vulnerability

Vista Windows.old

Windows Vista Remote Execution Vulnerability

Microsoft's Insecure Security - the Door for New Exploits

Internet Explorer 7 - Scarred By Vulnerabilities

Is Microsoft Sending the Right Signals for XP Users with Vista?

Vista vs. XP - Feature Comparison

Windows Vista System Restore

The World's First Fully Vista Powered Technology Community Worldwide

The $500 Million Windows Vista "Wow"

KMS Crack for Vista Home Basic and Home Premium

Windows Vista - a Sterile Operating System

Windows Ultimate Extra DreamScene Available

The MessageBox Vulnerability to Rain on Vista's Parade

It's Raining Word Vulnerabilities

New Windows Vista 3 Ways Crack

Kaspersky Reveals the Fundamental Vulnerability of Vista PatchGuard

Workaround Available for Clean Vista Installations Via Upgrade Keys

Windows Vista Causes Confusion Between "Secure" and "Security"

Windows Vista Home Basic, Home Premium, Business, Enterprise and Ultimate - Comparison

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM