Should Microsoft downgrade Vista vulnerabilities?
The man who wrote the book on Microsoft's highly rated SDL (Security Development Lifecycle) believes buffer-related security vulnerabilities found in Windows Vista should be downgraded because of back-up mitigations built into the operating system.
windows -
comments -
12.3.2007
New Round of Vista SP1 and XP SP3 Vulnerabilities
Microsoft is cooking patches for a new round of vulnerabilities impacting its Windows client and operating systems and Server software, including Windows Vista Service Pack 1 and Windows XP Service Pack 3.
windows -
comments -
4.7.2008
Microsoft delivers two patches for three vulnerabilities; Plugs Vista hole
Microsoft on Tuesday delivered one “critical” addressing two vulnerabilities in XP and Vista and one “important” vulnerability in Windows 2000, XP and Windows Server 2003.
windows -
comments -
8.1.2008
Windows 7 RTM Safe from Vista and XP Critical Vulnerabilities
When it launched Windows Vista back in January 2007, Microsoft made sure to emphasize added security as part of the Wow.
download -
comments -
12.8.2009
Microsoft Patches Critical Vista SP1 and XP SP3 Vulnerabilities
It's patching time yet again for Microsoft, as the software giant made available no less than eight security bulletins on December 9, 2008, designed to plug vulnerabilities in a range of products including Windows Vista Service Pack 1 and Windows XP Service Pack 3.
windows -
comments -
10.12.2008
New Security Solutions Live in Time for Vista SP1 and XP SP3 Vulnerabilities
October 14 was synonymous not only with the availability of a new release out of the Microsoft monthly patch cycle but also with the introductions of a couple of new security from the Redmond company: the Microsoft Active Protections Program (MAPP) and Exploitability Index.
download -
comments -
15.10.2008
Microsoft Patches 23 Vulnerabilities
As part of its monthly security update cycle, Microsoft on Tuesday released a dozen security bulletins. Nine of them are tagged critical, the company's highest severity rating. The alerts give details of 20 flaws in Windows and three in Office, all of which Microsoft has now fixed.
microsoft -
comments -
9.8.2006
Should Microsoft start paying for vulnerabilities?
Hackers are starting to agitate for Microsoft to start paying for information on security flaws found in its software products.
microsoft -
comments -
16.3.2007
ActiveX Is Vulnerable to Attacks Even Without Vulnerabilities
Internet Explorer users are vulnerable to attacks targeting ActiveX, even when ActiveX is vulnerability-free, claims security company Symantec.
microsoft -
comments -
11.8.2008
Windows XP SP3 Gets Its First Taste of Vulnerabilities
The third and final service pack for Windows XP is not even out the door, and security company Symantec has already warned of a security vulnerability impacting XP SP3.
windows -
comments -
7.4.2008
Microsoft drops 6 bulletins, fixing 11 vulnerabilities
Microsoft’s Patch Tuesday train arrived today with six bulletins covering at least 11 vulnerabilities, most carrying the company’s highest severity rating.
microsoft -
comments -
11.7.2007
Microsoft Patch Tuesday Fixes 10 Vulnerabilities
As expected, yesterday Microsoft rolled out five "critical" and three "important" patches for Windows Server 2008, Vista, Office, Internet Explorer and other software as part of its regularly scheduled Patch Tuesday release.
microsoft -
comments -
9.4.2008
How to Install Vista Language Packs MUI on all versions of Vista + video tutorial
Microsoft Windows Vista Home Basic, Vista Home Premium, and Vista Business versions of the Microsoft licensing restrictions can only preserve a language!
download -
comments -
23.9.2008
The Vista Built-in Super Administrator Account Has Survived in Vista SP1
Windows Vista Service Pack 1 is designed to evolve the RTM version of the latest Windows client from Microsoft, made available in November 2006 to business customers, and in January 2007 to the general consumers.
windows -
comments -
15.2.2008
Vista SP1 Is Out, XP SP3 Old News, the Pink Edition of Vista Is In
Windows Vista Service Pack 1 is now nothing more than water under the bridge, now that the service pack was released to manufacturing on February 4, 2008, shipping to general users on March 18.
windows -
comments -
27.3.2008
Tell Hasta la Vista to XP - Time to Upgrade to Vista SP1
Like it or not, this is the right time not only to upgrade to Windows Vista Service Pack 1 but also to tell hasta la vista to Windows XP.
windows -
comments -
30.6.2008
Instant Change Vista Product ID with Vista ProductID Changer
In past we have reviewed number of application to recover product key like Product Key Finder, WinGuggle, Windows product Key Finder.
download -
comments -
1.11.2009
Vista SP1 RC1 Flies Past Vista RTM and Windows XP SP2
Despite the fact that Microsoft has expressed its official position regarding testing Windows Vista Service Pack 1 ahead of its finalization, there is simply too much of a hunger for the service pack.
windows -
comments -
27.12.2007
Vista SP1 Won't Resolve the 4 GB RAM Limitation of 32-bit Windows Vista
32-bit Windows operating systems, and Windows Vista makes no exception whatsoever to this rule, are limited in terms of the amount of system memory that can be addressed to no more than 4 GB.
windows -
comments -
4.1.2008
Vista Loader 2.1.3 - Windows Vista Activator 2008 Support SP1 with No Boot String
Vista Loader is one of the most successful Vista activation crack available to date, second only to physical modify (hardmod) the BIOS to include SLIC table to make BIOS Vista activation-compliant.
download -
comments -
15.5.2008
x64 Vista SP2 JPG Rendering Performance Inferior to x86 Vista SP2's
The JPG rendering process on 64-bit flavors of Windows Vista Service Pack 2 is inferior to that on the 32-bit variants of the operating system.
windows -
comments -
10.6.2009
Microsoft to Kill the Grace Timer and OEM BIOS Windows Vista Cracks with Vista SP1
With the advent of Windows Vista, cracks also became available being designed to bypass the activation process of the operating system.
windows -
comments -
4.12.2007
New Vista OEM Activation Hack - Vista Boot by gkend
Thanks to Steve Jobs for this article on his blog and to our forum members to clecha, Nighthief and fitterphil120 for most of the findings. One again the “Chinese” come up with a new method to trick out the Vista Activation. We have seen Softmode and VistaLoader, however “ Vista Boot by gkend” does promise even more.
download -
comments -
21.5.2007
Windows Vista on Super Nintendo, As Real As Vista on PSP
We're puzzled and confused... How can a console that's at least ten times less powerful than the acclaimed PSP cope with Windows Vista's requirements?
windows -
comments -
15.8.2007
Vista RTM vs. Vista SP1 - Office 2007 benchmarking
Enough with benchmarking the OS - let’s see if Office 2007 is any faster on Vista SP1.
windows -
comments -
26.2.2008
Microsoft Says Vista SP1 Needs to Speak the Same Language as Vista RTM
Microsoft says that Windows Vista Service Pack 1 needs to speak the same language as the RTM version of the latest Windows client. Otherwise there's no game.
windows -
comments -
2.4.2008
Vista SP1 to Cure the Vista RTM Wow Hangover
When Windows Vista was unleashed in January 31, 2008, Microsoft was promising performance, security, innovation, all wrapped up under an umbrella of a Wow user experience.
windows -
comments -
11.4.2008
Vista-For-Free coupon with Vista ready PC's
Microsoft and the world's leading PC vendors have reached an agreement to promote the long-awaited Vista OS by offering PC buyers worldwide a free upgrade coupon, as a way of encouraging them to buy a Vista-capable PC as early as possible, according to market sources, citing information leaked from Taiwan-based PC makers.
windows -
comments -
11.10.2006
Can Vista SP1 help polish Vista’s tarnished image?
Call it complaining. Call it whining. The end result is the same: Windows Vista’s image is tarnished. And it’s corroding more and more rapidly as the weeks are going on. Thanks to pacpis for this news.
windows -
comments -
21.8.2007
Vista SP1 Features the Same Sins as Windows Vista
Windows Vista Service Pack 1 comes with the same sins as Windows Vista. The service pack is not even out the door, and is already putting users at risk.
windows -
comments -
16.1.2008Four New Browser Vulnerabilities Surface
Four new unpatched
vulnerabilities have been
published for Internet
Explorer and Firefox, with two
coming for each browser...
betanews.com -
05.06.2007Top 14 VoIP vulnerabilities
How are VoIP networks weak and vulnerable to attack and catastrophic failure? Securing VoIP Networks, the new book by Peter Thermos and Ari Takanen,
looks at VoIP infrastructure and analyzes its vulnerabilities much as the Open Web Application Security Project did for Web-related vulnerabilities
and Mitre did with its Common Weakness Enumeration dictionary for software. And its about human failings, too, not just technology problems.
Here are the top VoIP vulnerabilities explained in Securing VoIP Networks...
winbeta.org -
02.10.2007Vista Security Report Raises More Doubts Than It Relieves
A status report released
yesterday by the director of
Microsoft's Security
Technology Unit contends that,
over the first six months of
its shelf life, Windows Vista
was proven more secure than
its competitors during their
first six months, and more
secure than Windows XP after
its debut, by virtue of the
sole fact that fewer Vista
vulnerabilities were entered
into the National
Vulnerability Database...
betanews.com -
22.06.2007WabiSabiLabi may close 0day auction site
WabiSabiLabi may shut down its online marketplace for security vulnerabilities, focusing instead on the line of OneShield unified threat management
(UTM) appliances it developed with Italian defense company EuroTech.
Last year, WabiSabiLabi opened an online auction site for unpatched
security vulnerabilities, also called 0days. The company's stated aim was to provide a market that would allow independent security researchers to
earn a living from the vulnerabilities they discover. To prevent vulnerabilities from ending up in the hands of criminals, only qualified buyers are
permitted to use the WabiSabiLabi auction site.
While security companies routinely pay researchers for vulnerabilities and then keep this
information under wraps, some believe researchers should first disclose such vulnerabilities to vendors free and, when a patch is released, make
details of the vulnerability publicly available, a practice known in the security community as ethical disclosure.
Read full story.....
neowin.net -
30.10.2008Apple Fixes 50 Vulnerabilities in Mac OS, iPhone
Apple released a bevy of
patches for the Macintosh
operating system, as well as
its first patch for the iPhone
late Tuesday. Almost fifty
separate vulnerabilities have
been fixed as a result...
betanews.com -
01.08.2007Microsoft better at patching XP than Vista?
A Microsoft security executive
released data Thursday showing
that, six months after
shipping Windows Vista, his
company has left more publicly
disclosed Vista bugs unpatched
than it did with Windows XP.
In total, Microsoft has
patched 12 out of 27 disclosed
Vista vulnerabilities in the
six months after it first
shipped last November. During
XP's first six months,
Microsoft's security team
patched 36 out of 39 known
bugs. The data was published
by Jeff Jones, a Microsoft
security strategy director,
who said that overall, Vista
was doing better than XP.
"Windows Vista continues to
show a trend of fewer total
and fewer high-severity
vulnerabilities at the six
month mark compared to its
predecessor product, Windows
XP," he wrote.
Jones didn't address the
larger number of unpatched
vulnerabilities, but he did
note most of the unpatched
Vista bugs were not critical.
Microsoft had left only one
high-severity Vista
vulnerability unpatched during
the period. At the end of
XP's first six months, there
were two high-severity bugs
that were unpatched. Microsoft
patched 23 high-severity XP
bugs during its first six
months, compared with only one
high-severity Vista flaw.
Jones argued that Vista had a
lower number of
vulnerabilities than
competitive operating system
products such as Red Hat
Enterprise Linux and Mac OS X.
neowin.net -
23.06.2007Hackers will feed on Vista in 2008, says McAfee
Microsoft Corp. will face more than 40 vulnerabilities in Windows Vista next year, as the operating system climbs past the 10% market-share milestone
and malware authors really start to find flaws, a McAfee Inc. analyst said today.
"Most of the current malware has ignored
Vista," said Craig Schmugar, a threat researcher at McAfee's Avert Lab -- but that's not because the operating system has been frustratingly
secure. In fact, Schmugar argued, Vista has been a worthwhile target in the first year of its release.
"These people make their
living writing malware or attacking users," he said. "They're driven by financial motivation, and only when market share has an impact will they
really work on Vista."
At some point in 2008, Vista will own a tenth of the desktop operating system market, Schmugar predicted.
The milestone should mark the beginning of concerted efforts by attackers to root out vulnerabilities in the newer operating system. "Although the
huge market share that XP has means
will still be profitable there for years to come, Vista at 10% will put it on their radar," he said.
winbeta.org - 27.11.2007
H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk
This report looks at all of the vulnerabilities fixed by Apple, Microsoft, Red Hat and Ubuntu during the first half of 2008. At the vendor level, the
report examines all vulnerabilities as well as Days of Risk (DoR) associated with those vulnerabilities. The report further drills down to examine
just those issues affecting the commonly installed desktop operating system components.
winbeta.org - 27.10.2008
Adobe Patches Flash Vulnerabilities
Adobe this week fixed critical
vulnerabilities within its
Flash Player that could allow
an attacker to take control of
an affected system. According
to a company advisory, all
current versions of Flash 9, 8
and 7 are affected by the
problem, which relates to not
validating certain input...
betanews.com - 12.07.2007
Security vuln auction site pulls in research
A controversial marketplace for security exploits and vulnerabilities said it has exceeded expectations with the submission of more than 150
vulnerabilities in its first two months of operations.
WabiSabiLabi encourages security researchers to sell their findings to
vetted buyers. Herman Zampariolo, chief exec of WSLabi which runs the WabiSabiLabi marketplace, said that the quality of the submitted vulnerabilities
is as important as their quantity.
Vulnerabilities on the marketplace have had selling prices ranging between 100 to 15,000 euros
each. So far 1,000 sellers (researchers) have registered on the site.
winbeta.org - 13.10.2007
Microsoft Patches Multiple
Excel Flaws
Microsoft rolled out two
patches for vulnerabilities as
part of its monthly Patch
Tuesday effort, fixing six
vulnerabilities in Microsoft
Office, and a less significant
but still dangerous flaw
within Windows. Primarily
affected by the problems is
Excel...
betanews.com - 15.03.2006
Patch Tuesday: MS Fixes Glitches in IE, Multimedia, Vista
Microsoft released seven security bulletins that addressed 11 vulnerabilities on its Dec. 11 Patch Tuesday. Of those, three bulletins containing seven
client-side vulnerabilities are rated as critical and affect nearly all major Microsoft operating systems: 2000, XP, 2003 and Vista. " The more
alarming vulnerabilities are those in Windows Media Format Runtime and Internet Explorer, since a successful exploit could occur when a user visits a
malicious Web page or when viewing a malicious e-mail. Neither issue requires any further interaction by the victim to exploit, compounding the
problem, " Ben Greenbaum, senior research manager for Symantec Security Response, said in a release.
Of the vulnerabilities patched
was an issue in which a Macrovision driver incorrectly handled configuration parameters, allowing an attacker to take complete control of a vulnerable
system and install programs, view, change or delete data, or create new accounts with full user rights, Microsoft said in its advisory MS07-067.
Another important security advisory, MS07-066, involves a vulnerability in the Windows kernel that affects Vista. The flaw is an elevation of
privilege vulnerability in the way that Vista's Windows kernel processes certain access requests. The vulnerability could lead to an attacker
taking complete control of a target system.
neowin.net - 12.12.2007
5,198 Linux, Windows OS Flaws
in 2005
The United States Computer
Emergency Readiness Team
released its year-end summary
of computer vulnerabilities.
While Windows is regarded as
the most insecure operating
system, the US-CERT found four
times as many vulnerabilities
specifically related to Unix
and Linux...
betanews.com - 04.01.2006
Apple releases seven QuickTime fixes
Apple has patched seven vulnerabilities in the latest version of QuickTime affecting the Windows and MacOS X versions of the media player software.
Each of the vulnerabilities affects users of MacOS 10.3.9, 10.4.9 and 10.5 as well as Windows XP and Vista. Six of the vulnerabilities could allow
attackers to remotely execute code on the targeted machine.
neowin.net - 09.11.2007
US Treasury says IRS still hasn't fixed vulnerabilities in tax processing systems
Vulnerabilities in two IRS computer systems -- including the one developed to replace all existing tax processing systems at the agency -- were known
and repeatedly raised, but not addressed, during the nine-year development process...
betanews.com - 18.10.2008
Microsoft Issues 5 Critical Patches
November's Patch Tuesday has
brought with it five
"critical" patches
correcting 11 security
vulnerabilities, along with an
"important" fix for
two vulnerabilities related to
Novell's NetWare. Among the
list of patches is one for a
highly publicized flaw in
Microsoft's XML Core Services
component...
betanews.com - 15.11.2006
Mozilla Releases Hacker Tools
Mozilla is beginning to give
away programs used by both the
good guys and the bad guys to
discover critical program
vulnerabilities.
The
programs, called fuzzers, have
so far been for internal use
only. Fuzzers poke at programs
in search of vulnerabilities
that can arise when an
application receives data it
doesn't expect.
Programmers and
security researchers use them
to identify vulnerabilities
that they can then fix, or
warn people about. Online
crooks use them to find holes
that they can attack.
At the BlackHat
conference today, Mike Shaver
of Mozilla said the
open-source tools are
primarily meant to help other
programmers discover holes in
their own software...
winbeta.org - 03.08.2007
Microsoft Patches 7 Critical Vulnerabilities
As part of its Patch Tuesday
updates this week, Microsoft
corrected 10 vulnerabilities
in Windows and Office, 7 of
which were deemed
"critical." Three
critical flaws were fixed in
Excel that could allow for
remote code execution, while
one was fixed in Windows 2000
and Server 2003...
betanews.com - 11.07.2007
92% of Windows vulnerabilities can only occur on Administrator accounts
You know how everyone always says it's safer to run as a "Restricted" or "Standard" level user account?
Well, this is why.
According to John Moyer, the CEO of BeyondTrust Corp., 92% of critical security vulnerabilities in Windows, IE, and Office can only be exploited when
running as an Administrator user.
That's right, only 8% of critical vulnerabilities affect standard user accounts.
"This speaks to what enterprises should be doing," Moyer said. "Clearly, eliminating administrative rights can close the window of
opportunity of attack."
Of the 154 bugs published and patched by Microsoft in 2008, critical or not, 69% would have been blocked or
their impact reduced by configuring users to run without administrative rights, said the company.
When BeyondTrust looked at the
vulnerabilities patched for Microsoft's browser, Internet Explorer (IE), and its application suite, Office, it found that 89% of the former and 94%
of the latter could have been stymied by denying users administrative privileges...
jcxp.net - 04.02.2009
Microsoft Plans Six Security Updates, Two For Windows Vista
Gearing up for next
week's Patch Tuesday release,
Microsoft announced on
Thursday that it's preparing
six security updates -- four
of them for critical bugs.
One
security update actually can
patch multiple vulnerabilities
so it's unclear at this point
how many flaws next week's
releases will fix. Microsoft,
though, did announce in its
Security Bulletin Advance
Notification that each of the
four critical updates will
affect Windows software, while
only one affects Internet
Explorer. Another one will
address issues in Outlook
Express, as well as Windows
Mail.
One critical
vulnerability affects Windows
Mail in Windows Vista and
Windows Vista x64 edition.
There another patch for
Windows Vista that's rated
"moderate"...
winbeta.org - 08.06.2007