NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Windows Vista Remote Execution Vulnerability

Via speech recognition

By Marius Oiaga, Technology News Editor

1st of February 2007, 10:59 GMT

Adjust text size:


Just as Windows Vista has hit the shelves, Microsoft has confirmed the existence of a remote execution vulnerability in the operating system's speech recognition capabilities, and stated
that the matter is currently under investigation.

According to Microsoft, after the initial evaluation of public reports of the vulnerability, the flaw could allow the execution of verbal commands on a user's machine, with the same privileges as the user. "An issue has been identified publicly where an attacker could use the speech recognition capability of Windows Vista to cause the system to take undesired actions," revealed a representative of the Microsoft Security Response Center.

However, Microsoft claims that the vulnerability is only technically possible and that the users' exposure is limited. "In order for the attack to be successful, the targeted system would need to have the speech recognition feature previously activated and configured. Additionally the system would need to have speakers and a microphone installed and turned on. The exploit scenario would involve the speech recognition feature picking up commands through the microphone such as "copy", "delete", "shutdown", etc. and acting on them. These commands would be coming from an audio file that is being played through the speakers," added the MSRC representative.

Microsoft doubts the efficiency of such exploits due to the fact that they would have to be made at an audible level, and not concealed from the user. Additionally, by simply using voice functions, it is not possible to perform actions with elevated privileges or bypassing the UAC.

"The UAC prompt cannot be manipulated by voice commands by default. There are also additional barriers that would make an attack difficult including speaker and microphone placement, microphone feedback, and the clarity of the dictation," explained the MSRC representative.
Read by 1,007 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.4/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Anytime Upgrade

Windows Vista Is Unaffected by the VML Vulnerability

Symantec Explains the Vista CSRSS Vulnerability

Windows Vista Is Plagued with Vulnerabilities

Trojans Spread Via Zero-Day Word Vulnerability

The World's First Fully Vista Powered Technology Community Worldwide

Windows Home Server to Cure Digital Dysfunctions

The MessageBox Vulnerability to Rain on Vista's Parade

It's Raining Word Vulnerabilities

Windows Vista Service Pack 1 to Debut

Workaround Available for Clean Vista Installations Via Upgrade Keys

Windows Home Server to Integrate Seamlessly with Windows Vista

Windows Vista Maximum Supported RAM

Norton Will Be Ready in Time for Windows Vista

Medium Rating for Vista MessageBox Vulnerability

OneCare Beta Testers Get Discounts

Disable Tabbed Browsing in Internet Explorer 7

Windows Vista Home Basic, Home Premium, Business, Enterprise and Ultimate - Comparison

Merry Vista Vulnerability!

Security Insight on Windows Home Server

Windows Vista Will Not Be the Last Client OS from Microsoft

100,000 Computers Looking for Porn

Highly Critical Microsoft Word Zero-Day

Windows Live OneCare Is Incompatible with Windows Defender

Reset the Windows Vista Grace Period

Windows Vista International

Vista Is "Best Of CES"

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM