Windows has a 17 year old un-patched vulnerability
2 posters
Page 1 of 1
Windows has a 17 year old un-patched vulnerability
Windows has a 17 year old un-patched vulnerability
When it comes to updating security threats and bugs in their operating systems, Microsoft is, for the most part, pretty good about it. True, there are threats here and there that get overlooked, but eventually, Redmond takes care of them... except in this case.
The H Security points out that Microsoft has ignored a security hole in Windows since the release of Windows NT 3.1 in 1993. This vulnerability is present in all 32-bit Windows operating systems since then. The problem exists due to a flaw in the Virtual DOS Machine (or VDM), which was used to support 16-bit applications. The flaw allows for a 16-bit program to manipulate the kernel stack of processes. The site notes that "this potentially enables attackers to execute code at system privilege level," making this a real threat to system security.
A Microsoft spokesperson confirmed to Neowin that the company was investigating the "public claims of a possible vulnerability in Windows." The spokesperson also confirmed Microsoft was unaware of any attacks trying to use the "claimed vulnerability," or of customer impact. "Once we're done investigating, we will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves," they said.
The vulnerability was discovered by a member of the Google security team, named Tavis Ormandy. The hole was tested and found to still be present in Windows XP, Server 2003, 2008, Vista, and 7, and can be used to open a command prompt "in the system context, which has the highest privilege level." Ormandy says that he informed Microsoft of this hole back in 2009, but they have yet to fix it. The work around for it happens to be pretty simple; all you have to do is disable the MS-DOS subsystem. It's advised that all companies patch the hole, especially now that the vulnerability is public knowledge. Turning this off should not affect any compatibility issues, unless, for some strange reason, you're still using 16-bit applications.
Here's how to disable it:
"The workaround requires users to start the group policy editor and enable the "Prevent access to 16-bit applications" option in the Computer Configuration\Administrative Templates\Windows Components\Application Compatibility section."
SOURCE : Neowin
When it comes to updating security threats and bugs in their operating systems, Microsoft is, for the most part, pretty good about it. True, there are threats here and there that get overlooked, but eventually, Redmond takes care of them... except in this case.
The H Security points out that Microsoft has ignored a security hole in Windows since the release of Windows NT 3.1 in 1993. This vulnerability is present in all 32-bit Windows operating systems since then. The problem exists due to a flaw in the Virtual DOS Machine (or VDM), which was used to support 16-bit applications. The flaw allows for a 16-bit program to manipulate the kernel stack of processes. The site notes that "this potentially enables attackers to execute code at system privilege level," making this a real threat to system security.
A Microsoft spokesperson confirmed to Neowin that the company was investigating the "public claims of a possible vulnerability in Windows." The spokesperson also confirmed Microsoft was unaware of any attacks trying to use the "claimed vulnerability," or of customer impact. "Once we're done investigating, we will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves," they said.
The vulnerability was discovered by a member of the Google security team, named Tavis Ormandy. The hole was tested and found to still be present in Windows XP, Server 2003, 2008, Vista, and 7, and can be used to open a command prompt "in the system context, which has the highest privilege level." Ormandy says that he informed Microsoft of this hole back in 2009, but they have yet to fix it. The work around for it happens to be pretty simple; all you have to do is disable the MS-DOS subsystem. It's advised that all companies patch the hole, especially now that the vulnerability is public knowledge. Turning this off should not affect any compatibility issues, unless, for some strange reason, you're still using 16-bit applications.
Here's how to disable it:
"The workaround requires users to start the group policy editor and enable the "Prevent access to 16-bit applications" option in the Computer Configuration\Administrative Templates\Windows Components\Application Compatibility section."
SOURCE : Neowin
Marilyn- Senior memberz
- Posts : 107
Points : 6037
Reputation : 9
Join date : 2009-12-01
Re: Windows has a 17 year old un-patched vulnerability
How can they let something like that go unsolved for seventeen years? There has to be some reason why they didn't fix this back when the problem was initially addressed. My bet says they didn't want to risk their reputation admitting to having flawed security in their system.
Re: Windows has a 17 year old un-patched vulnerability
DukeAlastor wrote:How can they let something like that go unsolved for seventeen years? There has to be some reason why they didn't fix this back when the problem was initially addressed. My bet says they didn't want to risk their reputation admitting to having flawed security in their system.
Nobody can question Microsoft, or use linux - simple
Marilyn- Senior memberz
- Posts : 107
Points : 6037
Reputation : 9
Join date : 2009-12-01
Similar topics
» Microsoft confirms 17-year-old Windows bug
» Make Windows Xp Super fast : Windows Registry Tweak 5.0
» Texas 9-Year-Old Boy Hanged Self At School.
» 9 year old Indian girl becomes Microsoft Certified Professional
» Give 8-year-old rape victim, Na-Young, the justice she deserves
» Make Windows Xp Super fast : Windows Registry Tweak 5.0
» Texas 9-Year-Old Boy Hanged Self At School.
» 9 year old Indian girl becomes Microsoft Certified Professional
» Give 8-year-old rape victim, Na-Young, the justice she deserves
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum