NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Watch Windows Vista Vulnerabilities Grow

The count is on

By Marius Oiaga, Technology News Editor

11th of April 2007, 15:23 GMT

Adjust text size:



Enlarge picture
Are all Windows Vista vulnerabilities going to take over three months to be resolved? That is a bit harsh, but just let me explain. It will all make sense in the end, just bear with me. What I want
to focus on are two critical vulnerabilities impacting Windows Vista. The first is the Windows Animated Cursor Handling flaw, the second is the MsgBox (CSRSS) Remote Code Execution Vulnerability.

Both have been reported to Microsoft all the way back in December 2006. In this context, Microsoft thanked Alexander Sotirov of Determina Security Research for reporting the Windows Animated Cursor Remote Code Execution Vulnerability and Tim Garnett of Determina Security Research for reporting the MsgBox (CSRSS) Remote Code Execution Vulnerability. So Determina was at the source of the security updates Microsoft made available on April 3 and 10 patching the two critical vulnerabilities impacting Windows Vista.

As far as the Windows Animated Cursor Handling flaw is concerned, I have already tackled the subject, but the Message Box vulnerability was not overlooked. In fact, when I had the chance to talk with Stephen Toulouse, senior program manager for the Trustworthy Computing Group at the end of February, I specifically inquired about the MsgBox flaw. At that point, Microsoft was still investigating the issue.

Since December 2006 and April 2007, the MsgBox (CSRSS) Remote Code Execution Vulnerability has grown from a low severity rating vulnerability to a Critical level. Microsoft has also discovered to adjacent CSRSS vulnerabilities one that permits elevation of privileges and the other DoS attacks in the eventuality of a successful exploit. All three of them have been patched with Microsoft Security Bulletin MS07-021.

TAGS:

Windows Vista | vulnerability
Read by 1,991 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 10 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Is Top Dog

When Windows .ani Files Attack

Attackers Can Potentially Run Malicious Applications on Windows Vista

Firefox 2.0 and IE7 - Attack Vectors for Windows Vista

Windows Vista, 90-Day Vulnerability Report

Vista, Linux, Mac OS X - Apples, Apples, Apples?

A Windows Vista Zero-Day Is Pure Gold

Windows Vista Is Hard As a Rock

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM