NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Windows Vista Is Plagued with Vulnerabilities

Determina has identified a total of five vulnerabilities in Microsoft's products

By Marius Oiaga, Technology News Editor

27th of December 2006, 08:06 GMT

Adjust text size:


Microsoft is not a stranger to vulnerabilities, not even by far. And the fact that Windows Vista will not debut for the general public with an immaculate record comes to prove that Microsoft
cannot escape a tradition of vulnerabilities. Although the Redmond Company has labored extensively to make the platform synonymous with a secure environment, with a little over one month to the official launch of the operating system, there are numerous vulnerability reports associated with Vista.

Redwood City, California-based security company Determina has identified a total of five vulnerabilities in Microsoft's products, over the period beginning on December 15, 2006. The five security flaws detected by Determina are on top of the Client Server Run-Time Subsystem less critical vulnerability for which a Russian hacker has already published the Proof-of-Concept code, impacting Windows 2000 SP4, Windows Server 2003 SP1, Windows XP SP1, Windows XP SP2 and Windows Vista operating systems.

According to executives from Determina, the security company has also discovered the first critical vulnerability in Internet Explorer 7. "Web users could potentially become infected simply by visiting a site designed to exploit the flaw," said Alexander Sotirov, senior security researcher at Determina. "It allows any website you visit to gain control of your browser, execute code on your system and take control." Via this vulnerability, malware can be injected into Vista while the users surf a malicious website. Determina gave little additional details on the other vulnerabilities, but as soon as such details will be made available you will be able to read about them right here on Softpedia.

As yet, Microsoft has only commented on the Client Server Run-Time Subsystem vulnerability, and stated that the Redmond Company has not detected even limited exploit attempts and that a security patch is in the works.

"I don't think people should become complacent," said Nand Mulchandani, a vice president at Determina. "When vendors say a program has been completely rewritten, it doesn't mean that it's more secure from the get-go. My expectation is we will see a whole rash of Vista bugs show up in six months or a year."

Additionally, there is the case of the Windows Vista zero-day vulnerability that is being auctioned for $50,000 according to Raimund Genes, chief technology officer for security firm Trend Micro.

"A lot of businesses are not prepared for Vista because of the hardware that's needed. So, businesses may be slow to upgrade," said Dave Marcus, security research and communications manager for McAfee. "If you buy a zero-day exploit, you want it to work on a widely deployed piece of software."
Read by 1,139 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.0/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Anytime Upgrade

Trojans Spread Via Zero-Day Word Vulnerability

Microsoft's "Very Limited, Targeted Attacks"

Seven December 2006 Security Bulletins

Merry Vista Vulnerability!

Inspect OS and Software Security

Microsoft Confirms That Vista Is Affected by Malware from 2004

100,000 Computers Looking for Porn

The First Windows Vista Vulnerability

New Worm - Old Vulnerabilities

PoC Published for Internet Explorer 7 Vulnerability

Will Symantec's Security FOR Vista Work WITH Vista?

Exchange Server 2007 White Paper

Yes, Sophos Already Released Vista Anti-virus Protection

Microsoft Warns of Zero-Day Attacks

Windows Print Spooler 0day DoS Vulnerability

Vista-Compatible Security from Symantec

133 Critical and Important Microsoft Vulnerabilities

Windows Vista Teredo Protocol Vulnerability on Launching Day

The Limitations of Extended Validation SSL Certificates

Vista Is Neither Foolproof Nor Perfect

Attack Vectors in Windows Vista

The Third Exploit for Microsoft Word Vulnerability

Firefox 2.0 Continues to Grow in the Detriment of IE7

Internet Explorer 7 - Zero Vulnerabilities

Second Word Zero-Day Vulnerability in a Week

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM