Thursday, March 01, 2007

Windows Vista: Latest Vulnerability

While I was at work yesterday morning, I saw an email from . Headline: Latest Vulnerability found in Windows Vista. This definitely does not suprise me. Then later yesterday, there was a making fun of this vulerabiity of . Boy, how news travel, and Apple has reacted very quickly market wise to capitalize on this latest news.

According to the InfoWeek article, I quote, "The flaw, which is similar to a buffer overflow problem, is a privilege escalation bug, according to Marc Maiffret, co-founder and chief hacking officer of eEye Digital Security, an endpoint security company based in Aliso Viejo, Calif." Now buffer overflow problems is nothing new to the industry. use to happen on a regular basis, until we became more security conscious.

Of course like a buffer overflow problem, we have a priviledge escalation bug, which most likely is caused by an error in coding (i.e forgeting to check buffer space, or deallocating buffer space, etc). Thanks to the age old problem of buffer overflow, regular users in Vista, can now grab priviledges illegally, and have system level access, not just regular user access.

The good news is that the vulnerability does not apply to remote uers. However, if combine with other hacks, , spyware, this vulnerability can be extremely dangerous.



tags: , , , ,