KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Windows 7 RTM 7600.16385.090713-1255 HERE !

How to activate Windows 7 RC build 7600, 7264, 7231 and olders


New Vulnerability Found In Windows Vista

section: windows, for your questions: KezNews forum, 28.2.2007

    Tip: Click here to update all your PC's outdated drivers

A security vendor based in Aliso Viejo, California has found a vulnerability with a 'medium' security rating in Microsoft's Windows Vista.




The flaw, which eEye first reported as an Upcoming Advisory, is one of the first to be found in the brand new operating system. Earlier this month, Microsoft patched a flaw in Windows Defender, which is a built-in spyware and security component in different applications, including Windows XP and Vista. Maiffret points out that this new flaw is in the Vista operating system itself, not in a component that has been used in various programs.

eEye researches found the vulnerability on Jan. 9 and reported it to Microsoft on Jan. 19. Vista wasn't released for retail until the end of January.

The vulnerability enables regular users to grab more power on the system.

"A main security feature added to Vista is that regular users have a lower level of privileges," says Maiffret. "They have fewer privileges in Vista than they did in Windows XP. When regular users are running the operating system, they have regular user-level access, but with this vulnerability, you can elevate yourself to system-level access. Any normal user can do anything they want to the system."

Maiffret says they gave it a "medium" security rating because it doesn't enable a remote user to control the system. But he also says it wouldn't take much to elevate it.

"If it was coupled with a virus or a different remote vulnerability, it would be a lot more serious," he adds. "Viruses are very prevalent and there are plenty of other vulnerabilities you can couple it with. In a real world context, it's high because there are a lot of other things you can couple it with to make it pretty nasty. On its own, though, it's only medium."

A spokesman with Microsoft said researchers still are investigating the vulnerability.

View: KezNews Discussion - New Vulnerability Found In Windows Vista

source: informationweek

  >> Click Here to Run a Free Scan for PC Errors <<

send email Send link 2 friend  |  Permalink
<< previouse article
Windows Genuine Advantage Validation - WGA Patcher v1.7.17.0 Crack
next article >>
Microsoft sends out Windows Live Beta Community Invitation

MORE RELATED ARTICLES:
32-bit Windows 7, Vista, XP Affected by 17-Year-Old EoP Vulnerability || Windows has a 17 year old un-patched vulnerability || Windows 7 RC Immune to 0-Day DirectX Vulnerability || Zero-Day Windows 7 RTM DoS Vulnerability Has PoC Published in the Wild || Microsoft set to fix 17 year old Windows vulnerability next week

Comments(0)


No new comments are allowed for this article.

For your questions use our KezNews Discussion - New Vulnerability Found In Windows Vista