On MovieTome: TRANSFORMERS 2 SPOILERS!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Apr 4, 2007 11:00:00 AM

Microsoft's release of a "critical" patch on Tuesday poked holes in Vista's security promises, but security experts advise against discounting the new operating system.

The software giant broke with its monthly patch cycle Tuesday to fix a bug that cybercrooks had been using since last week to attack Windows PCs, including those running Vista.

"As far as software vulnerabilities go, Vista's cover is blown," said Nand Mulchandani, a vice president at Determina, the company that discovered the latest security bug. "It is not Superman; it is just a human being. It is just software. Vista is going to be very similar to the other operating systems Microsoft has delivered in terms of bugs."

Microsoft officially launched Vista for consumers in January, promoting the operating system as the most secure version of Windows yet. It is the first client version of Windows built with security in mind, meaning that it should have fewer coding errors that might be exploited in attacks, Microsoft has said.

Yet the "critical" hole that affected much older Windows versions also hit Vista. The vulnerability lies in the way Windows handles animated cursors and could let an attacker commandeer a PC when the user views a malicious Web site or e-mail message.

The cursor flaw lies in the operating system code. This means that any application that relies on the operating system to handle animated cursor files could be an attack vector. This includes alternative browsers, such as Firefox.

Click here to Play

Video: Hacking a Vista PC
Determina experts explain how to exploit animated-cursor flaw.

It is a flaw that should have been caught by Microsoft's code-vetting processes for Vista, called the Security Development Lifecycle, some experts said. The flaw is also evidence that faulty code from previous Windows versions has been copied into Vista, they said.

"It is a little premature to attack the whole effort altogether, but this is something that the Security Development Lifecycle should have caught," said Amol Sarwate, a research manager at vulnerability management company Qualys.

The buffer overflow vulnerability in the cursor function in particular should have already been fixed because a bug in the same Windows component was patched two years ago, said Rohit Dhamankar, manager of security research at TippingPoint, a seller of intrusion prevention products. That should have prompted re-examination of the code, Dhamankar said.

Microsoft disputes that it should have caught the cursor bug before. People who say so don't understand security vulnerabilities because not all bugs are created equal, said Stephen Toulouse, senior product manager in Microsoft's Security Technology Unit.

"In the case of the cursor vulnerability, even though something may look similar to the outside, that doesn't mean the code is anything alike to the previous vulnerability," Toulouse said. "The SDL was never meant to catch every single vulnerability, period."

But Dhamankar argues that Microsoft forgot to recheck all the possibilities that could lead to a buffer overflow after the original bug was found and patched in 2005.

Mulchandani agreed. "The dirty little secret is that Microsoft clearly did not write Vista from scratch. They did not completely build a whole new code base for this operating system. Every version of Windows since Windows NT has had this flaw in it," he said.

Microsoft does acknowledge that Vista will have vulnerabilities. "There are going to be other vulnerabilities. The SDL is not a process by which no vulnerabilities will ever occur. There is no process on this planet that can do that," Toulouse said.

The cursor flaw is like a sign post for the bug hunters. Hackers will now be looking for bugs in similar Windows components to find ways to attack Vista.

"This has been a very significant break and it definitely gives a big pointer," Dhamankar said. "If more such errors are found later, Vista is not going to be able to offer the great protection that's claimed."

Still, Microsoft's Vista security promise doesn't fall apart because of this single vulnerability. Vista is more secure than XP or any other Microsoft client operating system, Sarwate said. "If you consider Windows 2000, XP, 2003, I would still say that Vista is more secure than all the other operating systems," he said.

Mulchandani also said that, while Microsoft has taken way too big a bite at the security message, Vista is more secure than its predecessors because of features such as User Account Control and others that limit privileges on the operating system.

And that's just the goal Microsoft was aiming for, Toulouse said.

"You have to look at Vista versus XP. A lot of people are holding Vista up and saying in a vacuum it will reach some nirvana of security," Toulouse said. "Our whole goal with Windows Vista was to create a fundamentally more secure operating system than we have ever created previously."

  • Talkback
  • Most Recent of 342 Talkback(s)
EVH!
http://www.analogstereo.com/honda_prelude_owners_manual.htm... (Read the rest)
Posted by: yu_forum@... Posted on: 05/21/07 You are currently: Logged In | Log out
The problem seems to be expectation Scrat   | 04/04/07
Let's face it Spoon Jabber   | 04/04/07
I think it will be for the same reason xuniL_z   | 04/04/07
Yes, but to get that.... mypl8s4u2   | 04/04/07
I paid $750 for my Vista system ye   | 04/04/07
Premium content with DRM miyojim   | 04/04/07
What does that have to do with Aero? ye   | 04/04/07
Although 3.0 is fairly low on the Vista scale... Jeff Hayes   | 04/04/07
Big deal dolph0291   | 04/05/07
Lets' start with this... xuniL_z   | 04/06/07
"Mega RAM" M.R. Kennedy   | 04/04/07
Go to any bestbuy xuniL_z   | 04/04/07
CORRECTION, PRICES I LISTED ARE FOR xuniL_z   | 04/04/07
Did you ever play premium content? miyojim   | 04/04/07
I"m not even interested xuniL_z   | 04/06/07
Or they can buy a Mac Mini and Parallels and install Laff   | 04/04/07
Or , better yet..... xuniL_z   | 04/04/07
More? How so? Laff   | 04/04/07
Did you notice xuniL_z   | 04/04/07
How so... waterhzrd   | 04/04/07
Dependson the circumstances.... Laff   | 04/05/07
pagan Jim xuniL_z   | 04/06/07
bootcamp a hack? doh123   | 04/04/07
Please lookup definition of "hack" xuniL_z   | 04/04/07
no... you dont doh123   | 04/04/07
Ok, but how do I xuniL_z   | 04/06/07
Or , better yet..... uM0p ap!sdn   | 04/05/07
And why get stuck running only windows? dolph0291   | 04/05/07
Funny coming from a Mac defender NonZealot   | 04/04/07
You must be using two different currencies... Gordon Gonsalves   | 04/04/07
Ahem, Gordon, I'd say you DO need some education... Jeff Hayes   | 04/04/07
Ahem, Jeff, I'd say you DO need some education... uM0p ap!sdn   | 04/05/07
Here ya go... waterhzrd   | 04/04/07
Oh come on now dolph0291   | 04/05/07
Go Joe six-pack DIMrBobSir   | 04/04/07
Microsoft didn't set that expectation. ye   | 04/04/07
Oh, trust me . . . critic-at-arms   | 04/04/07
That's quite a reply xuniL_z   | 04/04/07
I'll trust you when you become objective. ye   | 04/04/07
Then you obviously don't trust yourself MacCanuck   | 04/04/07
Grow up. Is a "I know you are but what am I?" response... ye   | 04/04/07
Don't listen to him xuniL_z   | 04/04/07
"Ouch" MacCanuck   | 04/04/07
Don't listen to xuniL_z MacCanuck   | 04/04/07
Are you serious? xuniL_z   | 04/04/07
A "fantastic job of securing the OS" would be... jasonp@...   | 04/04/07
So, just out of curiosity... 3D0G   | 04/04/07
Trusted BSD, galileon   | 04/04/07
BZZZZTTT But thanks for playing. 3D0G   | 04/04/07
Sure .... The Smoking Man   | 04/04/07
Funny you label me an NBMer even though I'm posting... ye   | 04/04/07
Can I play too!? Linux User 147560   | 04/04/07
ummm....he wasn't playing. xuniL_z   | 04/04/07
I'll have to return the compliment. ye   | 04/04/07
Get a room! (NT) ;) Spoon Jabber   | 04/04/07
answer: THEY WILL! galileon   | 04/04/07
MAC is hardly used in Linux and not available in OS X. ye   | 04/04/07
You can run Linux and Windows using Parallels on a Mac. Laff   | 04/04/07
Psssst. Jim.....ummm xuniL_z   | 04/04/07
Real Answer Freebird54   | 04/05/07
Microsoft didn't set that expectation uM0p ap!sdn   | 04/05/07
What makes you think Vista's SP1 will be better than any other SP has been? critic-at-arms   | 04/04/07
Speaking of circuses xuniL_z   | 04/04/07
You can't "here" because you don't listen critic-at-arms   | 04/04/07
unsupportable xuniL_z   | 04/04/07
LOL! Eddie does rock! :) (NT) Spoon Jabber   | 04/05/07
Oh, the memories. (NT) xuniL_z   | 04/06/07
EVH! yu_forum@...   | 05/21/07
Oh, BTW, I'm not mad . . . critic-at-arms   | 04/04/07
Oh, BTW, I'm not xuniL_z   | 04/04/07
Wasn't it IBM? Spoon Jabber   | 04/04/07
I don't believe it was IBM or MS MacCanuck   | 04/04/07
What I was referring to was the fact xuniL_z   | 04/04/07
Depends on definition Freebird54   | 04/05/07
Wise choice. (NT) xuniL_z   | 04/05/07
Speaking of circuses uM0p ap!sdn   | 04/05/07
Keep dreaming mypl8s4u2   | 04/04/07
Buy a system with XP? 3D0G   | 04/04/07
Not at retail stores Spoon Jabber   | 04/04/07
Don't wjkahlssmd@...   | 04/05/07
Vista=Zune OSX=iPod An_Axe_to_Grind   | 04/04/07
OK, you have a Zune,.... Spoon Jabber   | 04/04/07
Here we go again ! Intellihence   | 04/04/07
Here we go again ! Intellihence SO.CAL Guy   | 04/04/07
What did you say ? Intellihence   | 04/04/07
For the record , that small footprint you speak of is what keeps me safe . Intellihence   | 04/04/07
Wow, look, another Microsoft zealot nix_hed   | 04/04/07
Tell me about it. xuniL_z   | 04/04/07
Ironic mlambert890@...   | 04/05/07
Ironic indeed dolph0291   | 04/05/07
hmmmm....Look at the thread Indeed. xuniL_z   | 04/06/07
list keeps on growing yu_forum@...   | 05/21/07
This guy knows nothing about OS security ralphrides   | 04/04/07
Here we go again ! Intellihence uM0p ap!sdn   | 04/05/07
Your comparisons do nothing more xuniL_z   | 04/04/07
The problem is not the software Chad_z   | 04/04/07
Because when they don't the ABMers whine ye   | 04/04/07
Actually . . . critic-at-arms   | 04/04/07
Stop trying to glue on new features? ye   | 04/04/07
No conflict -- I've always been with you on this one critic-at-arms   | 04/04/07
I haven't had nearly the problems with Windows... ye   | 04/04/07
Were you using NT 4.0 pre or post SP3 ??? mrlinux   | 04/04/07
I've been using NT since 3.1 ye   | 04/04/07
I haven't had nearly the problems with Windows... uM0p ap!sdn   | 04/05/07
I second that A_Selby   | 04/05/07
mission critical xuniL_z   | 04/04/07
Windows BIAS andy40au@...   | 04/04/07
BIAS? Coming from you xuniL_z   | 04/05/07
MS cannot fix bugs, because there are too many miyojim   | 04/04/07
Hear Hear! andy40au@...   | 04/04/07
no, its old code never meant for modern secuity ralphrides   | 04/04/07
Absutely none from anyone with a clue... jasonp@...   | 04/04/07
Except that in the case of Vista... miyojim   | 04/04/07
The real facts are xuniL_z   | 04/05/07
Vista compatibility yu_forum@...   | 05/21/07
Just damned annoying Chad_z   | 04/04/07
Dirty little secret?? DavidMowers   | 04/04/07
Well said! (NT) Loverock Davidson   | 04/04/07
Agreed critic-at-arms   | 04/04/07
NT derives from VMS, from DEC miyojim   | 04/04/07
Experience the wow? macdonalds   | 04/04/07
nah, the WOW is more like... nix_hed   | 04/04/07
Time for a change, Apple does not DRM its OS ralphrides   | 04/04/07
Talk about spin....you are right there with the zealots. xuniL_z   | 04/06/07
Cursor flaw gives Vista security a black eye Loverock Davidson   | 04/04/07
How are you this morning , have the black eyes gone away ? Intellihence   | 04/04/07
Comment Spoon Jabber   | 04/04/07
I would never think of Intellihence being George Ou... bportlock   | 04/04/07
LOOK EVERYONE!@#*&#@#! HE MENTIONS ME!!! Loverock Davidson   | 04/04/07
The voices in your head don't count Shelendrea   | 04/04/07
I would never think it either xuniL_z   | 04/04/07
Intellihence just so you know read this SO.CAL Guy   | 04/04/07
Good idea, let's compare Spoon Jabber   | 04/04/07
Hehehe mg156   | 04/04/07
Let us compare Loverock Davidson   | 04/04/07
Work with me Spoon Jabber   | 04/04/07
And why is that subjective xuniL_z   | 04/04/07
Subject to opinion Spoon Jabber   | 04/05/07
Like this! Spoon Jabber   | 04/05/07
Apple zealots are not going to like you!! xuniL_z   | 04/05/07
I'm an equal opportunity offender! ;) (NT) Spoon Jabber   | 04/05/07
LOL A_Selby   | 04/05/07
Did you notice you gave away the "dirty little secret"? deleweye   | 04/04/07
Flaws in your post Loverock Davidson   | 04/04/07
Sorry but read the FA again... Linux User 147560   | 04/04/07
I did Loverock Davidson   | 04/04/07
But you're missing the point thetargos   | 04/04/07
You seem to have lost count??? xuniL_z   | 04/05/07
I was wrong - you don't know how they do it. deleweye   | 04/04/07
Did you notice you gave away the "dirty little secret"? SO.CAL Guy   | 04/06/07
Windoze security critic-at-arms   | 04/04/07
It's still disappointing... RocketEater   | 04/04/07