17 year old Windows bug

Started by Glenn, Jan 20, 2010, 11:22:21

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Glenn

A security researcher at Google is recommending computer users make several configuration changes to protect themselves against a previously unknown vulnerability that allows untrusted users to take complete control of systems running most versions of Microsoft Windows.

The vulnerability resides in a feature known as the Virtual DOS Machine, which Microsoft introduced in 1993 with Windows NT, according to this writeup penned by Tavis Ormandy of Google. Using code written for the VDM, an unprivileged user can inject code of his choosing directly into the system's kernel, making it possible to make changes to highly sensitive parts of the operating system.

http://www.theregister.co.uk/2010/01/19/microsoft_escalation_bug/
Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Simon

I'm sure, if these security researchers spend long enough, they will find minute bugs practically anywhere.  Doesn't mean anyone's going to try to expliot them.
Simon.
--
This post reflects my own views, opinions and experience, not those of IDNet.

Rik

But it also doesn't mean that someone won't.
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

somanyholes

Just a note. This is for privilege escalation not remote exploitation.

esh

It's also not in 64-bit windows. Yay!

I had some problem about a year ago when some old software we ran would not work anymore because of... copy protection using 16-bit ASM code which Windows did not emulate correctly :(
CompuServe 28.8k/33.6k 1994-1998, BT 56k 1998-2001, NTL Cable 512k 2001-2004, 2x F2S 1M 2004-2008, IDNet 8M 2008 - LLU 11M 2011