KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Vista Still Breathing as XP Chokes on Latest Vulnerability


section: windows, for your questions: KezNews forum, 7.11.2007

Windows Vista is still breathing as Windows XP is now choking on the latest vulnerability to hit Microsoft's platform. The Redmond company issued a security advisory detailing a flaw residing in the Macrovision SECDRV.SYS driver that ships by default with both Windows XP and Windows Server 2003.




Vista was not nominated along with the two operating systems impacted by the vulnerability and security company Symantec backed Microsoft's position revealing that the Redmond company's latest operating system is indeed immune to exploits targeting the flaw.

"The original exploit was found in the wild and actively used against Windows-based computers to gain SYSTEM privileges and install additional malware or bypass other restrictions. It wasn’t just proof-of-concept code, but a malicious exploit used in real (but limited) attacks. Vista is not affected. Only SECDRV versions shipped with Windows XP and 2003 are. Instead the version shipped with Vista is a completely different driver, reworked and not vulnerable to this attack. We have tested versions of SECDRV.SYS taken from different systems," revealed Elia Florio, Symantec Security Response Engineer.

Florio confirmed that only the versions of the driver that shipped with Windows XP and Windows Server 2003 contain the security hole, for which Macrovision is already offering a remedy. So far, Microsoft has not given any specific indication pointing to a possible inclusion of the patch issued with the next batch of security bulletins scheduled for next week. Symantec warned that – despite the fact that the vulnerability is only locally exploitable – attacks could leverage alternative avenues in order to successfully allow for remote code execution.

"The exploit can overwrite memory locations in the kernel, so the attacker can execute code in ring-0. This means that bad guys can bypass security restrictions, gain additional privileges, disable security protections, install a rootkit etc", Florio added. "All users should keep in mind that, in a multi-layered defense perspective, it is possible that malware dropped on the system via some other exploit, could potentially take advantage of the SECDRV bug to take further control of the computer and bypass other layers of protection."

source: news.softpedia.com

send email Send link 2 friend  |  Permalink
<< previouse article
Bill Gates, Steve Jobs, Michael Dell Top List of IT Influencers
next article >>
Windows Live Installer 12.0.1471.1025

MORE RELATED ARTICLES:
Latest Vulnerability Attacks Steer Clear of Vista SP1, but Not XP SP3 || The First XP SP3 Security Vulnerability || Windows Vista One Year Vulnerability Report || Windows Vista One Year Vulnerability Report || Microsoft acknowledges Vista kernel elevation vulnerability

Comments(5)

XP may choke now! but...

By Sonya on 08.11.2007 - 18:11
vista is already dead! i'm so glad i rid out of it!!!

TO: Sonya

By Macman on 08.11.2007 - 20:11
i agree my friend.

system: mac mini core2duo 2.0ghz 1gb/120gb/sd
os: leopard

lolmacs

By ^ on 08.11.2007 - 21:11
lolmacs


XP will die off

By IT NOD on 09.11.2007 - 21:11
i think that xp has been excellent but it's time to change and with sp1 out next year vista can only get better but who knows lets see but i have been a beta tester for vista and quite like it. but xp still rules!

MAC PAWNAGED!!! RLOF FSDFJKADKKLA

By DAMAN WHO RAPES XP on 09.11.2007 - 22:11
so how are those emulators running on macs fanboyes? jk! lol. but seriously theres postives and negatives to every os. you just have to pick the one you're willing to live with. i'd take xp over mac anyday of the week just for emulation and games in general. if you're not a gamin nut like me i guess mac is a good solution too...... just stop being fanboyes because it's pointless.... (kinda pointless sayin this to fanboyes though...)


No new comments are allowed for this article.

For your questions use our KezNews Forum