Advertisement
Promo

Security threats Toolkit

Microsoft admits to Vista flaw

Graeme Wearden ZDNet.co.uk

Published: 27 Dec 2006 14:17 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is investigating a security vulnerability which affects Vista, its newly launched operating system.

Mike Reavey, operations manager at Microsoft’s Security Response Center, revealed last Friday that Vista is vulnerable to a flaw that allows a malicious hacker to escalate user privileges within several versions of Windows.

Proof-of-concept code that exploits the code has been posted online, Reavey said in a blog posting, adding that Microsoft isn't yet aware of any malware that takes advantage of it.

"Initial indications are that in order for the attack to be successful, the attacker must already have authenticated access to the target system," wrote Reavey.

"While I know this is a vulnerability that impacts Windows Vista I still have every confidence that Windows Vista is our most secure platform to date. As always, we here at the MSRC encourage everyone to enable a firewall, apply all security updates and install anti-virus and anti-spyware software," he added.

Vista is Microsoft's first operating system release in five years. The company had repeatedly emphasised that it is more secure than previous versions, having been extensively rewritten.

One major change in Vista is that users accounts are created with administrator privileges turned off by default, unlike in XP where they are automatically turned on. Microsoft has cited this change as a key security change, as these administrator powers can be used to turn off other security measures.

As such, this flaw could put Vista users at risk. However, Mikko Hyppönen, chief research officer with Finnish security company F-Secure, has already said that the flaw it should not concern corporate or individual users as a malicious hacker can't take advantage of it unless they already have access to their machine.

Earlier this month, security firm Trend Micro claimed that a zero-day Vista flaw was being sold online for $50,000 (£25,500).Vista was launched to businesses at the end of November. It will go on sale to consumers in early 2007.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
244 out of 341 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters