NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Windows Vista Vulnerable to Attacks via UNIX

Through Windows Services for UNIX and in the Subsystem for UNIX-based Applications

By Marius Oiaga, Technology News Editor

7th of September 2007, 06:57 GMT

Adjust text size:



Enlarge picture
Microsoft's latest and most secure platform to date, Windows Vista, is vulnerable to attacks targeting a vulnerability residing in Windows Services for UNIX and in the Subsystem for UNIX-based Applications. However Vista is not the only product affected by the issue. Windows Services for UNIX provides a vector of attack for Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, Windows Server 2003 Service Pack 2. Additionally Windows Server 2003 x64 Edition and both the 32-bit and 64-bit editions of Windows
Server 2003 Service Pack 2 and Windows Vista can be compromised through Subsystem for UNIX-based Applications.

Through the successful exploitation of the UNIX-related security flaw on Windows, an attacker can perform elevation of privileges on Vista and the other affected operating systems. This is why Microsoft has labeled the vulnerability with a severity rating of Important. The information was officially confirmed by Microsoft, via the Security Bulletin Advance Notification for September 2007.

For September Microsoft is cooking a total of five security bulletins, one cataloged as Critical and the remaining four considered only of an Important level. September is proving a slow month for the Redmond company in terms of security patches. Microsoft will address in this month's patch cycle Critical vulnerability/vulnerabilities only in Windows 2000. This is the sole case where remote code execution is the result of an exploit.

Christopher Budd, security program manager in the Microsoft Security Response Center (MSRC) made public the complete list of security bulletins scheduled to go live on September 11. "As we do each month, as part of our processes to help make security updates more predictable and assist with your planning, we've posted our Advance Notification with preliminary information about next week's release. As a reminder, we provide this early information to help with planning, but it can change between now and next Tuesday. As part of our regularly scheduled bulletin release, we're currently planning to release five security bulletins," Budd stated.

Microsoft will patch Windows, Visual Studio, Windows Services for UNIX and the Subsystem for UNIX-based Applications, MSN Messenger, Windows Live Messenger and Windows and Microsoft SharePoint Server.

TAGS:

Windows Vista | Windows | vulnerability | Microsoft | UNIX
Read by 1,503 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.2/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


The Evolution of the Windows Vista Security Center

Windows Vista Will Be Immaculate after SP1

Microsoft: Vista! Vista! Vista!

Vista Growing to Match the Lack of Security of XP, Mac OS X and Linux

Windows Vista, Office 2007 and Internet Explorer 7 Are All Flawed!

McAfee Goes into Every Kiosk for XP Embedded - Vista Ignored

The Next Level of the Absurd in Windows Vista

Vista Still Insecure, Even After Microsoft Threw at It the Resources of a Small Country

Vista Security = Zero for Microsoft

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM