Microsoft acknowledges Vista kernel elevation vulnerability
section: windows, for your questions: KezNews forum, 15.12.2007
What was not supposed to happen in Windows Vista apparently has: Despite a layer of protection that was supposed to prevent against processes elevating their own privileges, Microsoft now says someone found a way to do it.
A Microsoft security bulletin written earlier this week but publicized this morning cites security software engineers SkyRecon Systems as having discovered a way for processes in both 32- and 64-bit versions of Windows Vista to elevate their own privilege to administrator level.
This discovery would likely be the latest in several months to thwart the designs of PatchGuard, Microsoft's series of measures for innovating the design of the operating system kernel in the interest of thwarting the most common attacks that plagued Windows XP. Last February, PatchGuard was theoretically defeated, using methodology made public by, ironically, Symantec.
Precise details of this latest vulnerability have not been released by either Microsoft or SkyRecon, most likely to protect the system. However, security engineers who have communicated with SkyRecon report the problem involves the Advanced Local Procedure Call (ALPC) system, which was updated for Vista to take advantage of the new kernel setup. Apparently a legacy provision for handling local procedure calls (as opposed to remote procedure calls, or RPCs) made the old-fashioned way, gave improper feedback which could be used in an exploit.
Microsoft has issued a security patch that addresses the ALPC issue.
source:
betanews.com
Send link 2 friend | Permalink
MORE RELATED ARTICLES:
New Kernel for Vista SP1, New Kernel for Windows 7 || Microsoft junks and replaces Vista kernel in SP1 || Looking beyond XP SP3 and Vista SP1 - Understanding the MinWin Kernel in Windows 7 || Is MinWin really the new Windows 7 kernel? || Windows Vista One Year Vulnerability Report
Comments(5)
once more the bug beats the can of raid.
i cant believe the issues vista has,it's
incredible how could a company like microsoft,think it was ready for the market.
it
has more holes then a flute...
peace \/
let's see...
6 billion dollars invested into vista...
dvd sized install
needed...
and that's all after v3, v95, v95 se, v98, v98 se, v2000, vxp...
so you would think surely by now, if security was an need, they would have done it by
now?
let's face it, microsoft isn't a security business... they just sell
crapy bloated software, that they don't want anyone to know, to have their source code
looked over, checked and reviewed by the public...
and you wonder why windows
isn't secure?
would you expect to sell software that is secure by denying
everyone the right to review the source code?
meaning no way to improve, fix or
refine the code... just pray and hope microsoft does this for you...
and how
many years has it been already?
i think there is not such a thing as a secure os and there never will be.
doesent
matter whatever a programmer will do there will always be another programmer to defeat his
code.
proof is all the attempts by microsoft at preventing people running a pirated
version.
they have not succeded yet and they will never succeed, despite all the
resources they put intto the attempt.
did you know most automobiles use a computer? yes, and you don't even worry about it,
having the need to use antivirus, spyware and so forth...
computer are used in
many devices, but when it comes to microsoft software, we all worry, not because it's
software, but because of how even microsoft has proven a track record of failures...
linux which is free doesn't have the security issues microsoft has been charging
it's customers. that's a fact.
linux has open source code, allowing everyone
to publically reveiw the code, so this allows everyone to check and change if required.
microsoft source code is not made available to the public, and there is no
method for the public to review the source code.
everyone using windows must
pray and hope microsoft will fix your code instead.
sinbce microsoft was
never about security to begin with nor is it today, why have your source code applications
and operatinbg system be coded by them?
you want to date the devil and say
angel?
we have many secure computers already, and whoeer said above there is no
such thing, as an secure os your an idiot.
what you need to say is rather how
difficult it is to secure open communications in an enviroment of untrusted computers
using a global network. but even so, most of the security issues are nothing more than
lame coders and lame individuals not being responsible for how they use a computer,
especially over a network.
this issue about security must be meet by social,
and micorosft isn't going to care when it earns billions of dollars in profits not to
provide real security.
example, microsoft's firewall, is lame. it only
protects one direction... if it's even turned on...
windows has so many bugs,
everyone has experienced blue screen crashes... your don't even need to be connected to
the internet for this to happen...
how can you expect a business only caring
abot making money who has and isn't a business about security to create security
software?
why not ask your english children to speak chinese, right?
microsoft's thinking is to translate english into chinese using google regarding
security.
nobody has ever said microsoft was ever a security business...
making secure software...
security is about trust, and there can be no trust
when responsibility os thrown right out the door...
would you trust your
american teenager daughter to be out on a date pass midnight at some man's apartment?
would you call that security?
what do americans know about
security anyhow? or even the chinese?
fsb (russia) has better security than
both combined together...
as unlike chinese russia hasn't a billion
individuals to talk and unlike america isn't willing to sell state secrets to the highest
bidder...
do you think car's software are not hacked ?.
its not because linux is open source
it cannot be attacked.
if there is so few attempts at a linux os is simply because
ther are so few linux running.
the same with mac.
No new comments are allowed for this article.
For your questions use our KezNews Forum
Yet again...
By rucamx PT on 16.12.2007 - 01:12