NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Windows Vista Is Unaffected by the VML Vulnerability

Michael Howard explains why

By Marius Oiaga, Technology News Editor

11th of January 2007, 09:47 GMT

Adjust text size:


Michael Howard is a Security Product Manager with Microsoft. Following Microsoft's January release of the company's monthly security bulletins, Howard addressed the relation between
a vulnerability in Vector Markup Language that could allow Remote Code Execution and Windows Vista on his blog.

Microsoft Security Bulletin MS07-004 specifies that Windows Vista is not affected by the VML vulnerability. The patch released by Microsoft on January 9, 2007 addresses only Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows XP Professional x64 Edition, Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1, Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 x64 Edition.

“The bug is an integer overflow calling C++ operator::new, but the affected component vgx.dll is compiled with the C++ compiler available in Visual Studio 2005 that automatically detects integer overflows at runtime. All of Windows Vista is compiled with this compiler,” is Howard's explanation for Vista's immunity when it comes to the VML vulnerability.

Michael Howard revealed that Windows Vista contains the coding bug. But the fact that the operating system has integrated the VS 2005 compiler means that Vista will not be susceptible of an integer overflow that will allow remote code execution.

As a self entitled “Simple Security Guy at Microsoft,” Michael Howard also identified a conclusion in this experience. “The moral of this story is developers will never find all code-level security bugs, so you need other defenses. Just in case,” he noted.
Read by 1,146 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.1/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Debuts the 2007 Patching Season

Windows Vista Vulnerabilities

Windows Vista Is Plagued with Vulnerabilities

Kaspersky Unveils Support for Windows Vista

133 Critical and Important Microsoft Vulnerabilities

Inspect OS and Software Security

Merry Vista Vulnerability!

Could Microsoft Have Controlled the Vista Vulnerabilities?

Internet Explorer 7 - Zero Vulnerabilities

Fingerprint Windows Vista

Internet Explorer Sinks Under 80%

Vista Is "Best Of CES"

Security Insight on Windows Home Server

Medium Rating for Vista MessageBox Vulnerability

Windows Vista & IE7 Vulnerabilities Cost from $8,000 to $12,000

The First Windows Vista Vulnerability

8 Microsoft Security Bulletins in January

Download BlackLight Rootkit For Windows Vista

Symantec Wants Control Over Vista's UAC

Windows Vista Anytime Upgrade

Windows Live OneCare Released to Manufacturing

Install Visual Studio 2005 SP1 on Windows Vista

Attack Vectors in Windows Vista

Highly Critical PDF Vulnerability

Microsoft to Handle the Vista Timer 2099 Crack

Seven December 2006 Security Bulletins

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM