KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Microsoft acknowledges Vista kernel elevation vulnerability


section: windows, for your questions: KezNews forum, 15.12.2007

What was not supposed to happen in Windows Vista apparently has: Despite a layer of protection that was supposed to prevent against processes elevating their own privileges, Microsoft now says someone found a way to do it.




A Microsoft security bulletin written earlier this week but publicized this morning cites security software engineers SkyRecon Systems as having discovered a way for processes in both 32- and 64-bit versions of Windows Vista to elevate their own privilege to administrator level.

This discovery would likely be the latest in several months to thwart the designs of PatchGuard, Microsoft's series of measures for innovating the design of the operating system kernel in the interest of thwarting the most common attacks that plagued Windows XP. Last February, PatchGuard was theoretically defeated, using methodology made public by, ironically, Symantec.

Precise details of this latest vulnerability have not been released by either Microsoft or SkyRecon, most likely to protect the system. However, security engineers who have communicated with SkyRecon report the problem involves the Advanced Local Procedure Call (ALPC) system, which was updated for Vista to take advantage of the new kernel setup. Apparently a legacy provision for handling local procedure calls (as opposed to remote procedure calls, or RPCs) made the old-fashioned way, gave improper feedback which could be used in an exploit.

Microsoft has issued a security patch that addresses the ALPC issue.

source: betanews.com

send email Send link 2 friend  |  Permalink
<< previouse article
Disabling UAC Slows Vista's Bootup Time?
next article >>
Office 2008 Hits RTM

MORE RELATED ARTICLES:
New Kernel for Vista SP1, New Kernel for Windows 7 || Microsoft junks and replaces Vista kernel in SP1 || Looking beyond XP SP3 and Vista SP1 - Understanding the MinWin Kernel in Windows 7 || Is MinWin really the new Windows 7 kernel? || Windows Vista One Year Vulnerability Report

Comments(5)

Yet again...

By rucamx PT on 16.12.2007 - 01:12
once more the bug beats the can of raid.
i cant believe the issues vista has,it's incredible how could a company like microsoft,think it was ready for the market.
it has more holes then a flute...

peace \/

Microsoft isn't a Security Business

By Kevin on 16.12.2007 - 22:12
let's see...

6 billion dollars invested into vista...
dvd sized install needed...
and that's all after v3, v95, v95 se, v98, v98 se, v2000, vxp...

so you would think surely by now, if security was an need, they would have done it by now?

let's face it, microsoft isn't a security business... they just sell crapy bloated software, that they don't want anyone to know, to have their source code looked over, checked and reviewed by the public...

and you wonder why windows isn't secure?

would you expect to sell software that is secure by denying everyone the right to review the source code?

meaning no way to improve, fix or refine the code... just pray and hope microsoft does this for you...

and how many years has it been already?



What is security ?

By xavier on 17.12.2007 - 05:12
i think there is not such a thing as a secure os and there never will be.
doesent matter whatever a programmer will do there will always be another programmer to defeat his code.
proof is all the attempts by microsoft at preventing people running a pirated version.
they have not succeded yet and they will never succeed, despite all the resources they put intto the attempt.

Security = Responsibility

By Samatha H. on 17.12.2007 - 21:12
did you know most automobiles use a computer? yes, and you don't even worry about it, having the need to use antivirus, spyware and so forth...

computer are used in many devices, but when it comes to microsoft software, we all worry, not because it's software, but because of how even microsoft has proven a track record of failures...

linux which is free doesn't have the security issues microsoft has been charging it's customers. that's a fact.

linux has open source code, allowing everyone to publically reveiw the code, so this allows everyone to check and change if required.

microsoft source code is not made available to the public, and there is no method for the public to review the source code.

everyone using windows must pray and hope microsoft will fix your code instead.

sinbce microsoft was never about security to begin with nor is it today, why have your source code applications and operatinbg system be coded by them?

you want to date the devil and say angel?

we have many secure computers already, and whoeer said above there is no such thing, as an secure os your an idiot.

what you need to say is rather how difficult it is to secure open communications in an enviroment of untrusted computers using a global network. but even so, most of the security issues are nothing more than lame coders and lame individuals not being responsible for how they use a computer, especially over a network.

this issue about security must be meet by social, and micorosft isn't going to care when it earns billions of dollars in profits not to provide real security.

example, microsoft's firewall, is lame. it only protects one direction... if it's even turned on...

windows has so many bugs, everyone has experienced blue screen crashes... your don't even need to be connected to the internet for this to happen...

how can you expect a business only caring abot making money who has and isn't a business about security to create security software?

why not ask your english children to speak chinese, right?

microsoft's thinking is to translate english into chinese using google regarding security.

nobody has ever said microsoft was ever a security business... making secure software...

security is about trust, and there can be no trust when responsibility os thrown right out the door...

would you trust your american teenager daughter to be out on a date pass midnight at some man's apartment?

would you call that security?

what do americans know about security anyhow? or even the chinese?

fsb (russia) has better security than both combined together...

as unlike chinese russia hasn't a billion individuals to talk and unlike america isn't willing to sell state secrets to the highest bidder...



Security = Responsibility

By xavier on 18.12.2007 - 05:12
do you think car's software are not hacked ?.
its not because linux is open source it cannot be attacked.
if there is so few attempts at a linux os is simply because ther are so few linux running.
the same with mac.


No new comments are allowed for this article.

For your questions use our KezNews Forum