Technology Questions

Go Back   Technology Questions > Software Questions > Operating System Questions > Vista Community > Windows Vista

Windows Vista Discuss the different versions of Windows Vista, Fuji, or Vienna

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 12-17-2007, 02:01 AM
occam
Newsgroup Contributor
 
Posts: n/a
Microsoft acknowledges Vista kernel elevation vulnerability

[url]http://www.neowin.net/news/main/07/12/16/microsoft-acknowledges-vista-kernel-elevation-vulnerability[/url]

---

What was not supposed to happen in Windows Vista apparently has: Despite
a layer of protection that was supposed to prevent against processes
elevating their own privileges, Microsoft now says someone found a way
to do it.

A Microsoft security bulletin written earlier this week but publicized
this morning cites security software engineers SkyRecon Systems as
having discovered a way for processes in both 32- and 64-bit versions of
Windows Vista to elevate their own privilege to administrator level.
This discovery would likely be the latest in several months to thwart
the designs of PatchGuard, Microsoft's series of measures for innovating
the design of the operating system kernel in the interest of thwarting
the most common attacks that
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 12-17-2007, 02:01 AM
  #2 (permalink)  
Old 12-17-2007, 04:50 AM
Mike Hall - MVP
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft acknowledges Vista kernel elevation vulnerability

Its sad that there are some people who work 24/7 specifically to make life
difficult for computer users. No matter what is created to protect us, some
jackass is going to try to break it.

--
Mike Hall - MVP
[url]http://msmvps.com/blogs/mikehall/default.aspx[/url]




"occam" <occam@razor.dot.com> wrote in message
news:eEJRkJJQIHA.5360@TK2MSFTNGP03.phx.gbl...[color=blue]
> [url]http://www.neowin.net/news/main/07/12/16/microsoft-acknowledges-vista-kernel-elevation-vulnerability[/url]
>
> ---
>
> What was not supposed to happen in Windows Vista apparently has: Despite a
> layer of protection that was supposed to prevent against processes
> elevating their own privileges, Microsoft now says someone found a way to
> do it.
>
> A Microsoft security bulletin written earlier this week but publicized
> this morning cites security software engineers SkyRecon Systems as having
> discovered a way for processes in both 32- and 64-bit versions of Windows
> Vista to elevate their own privilege to administrator level. This
> discovery would likely be the latest in several months to thwart the
> designs of PatchGuard, Microsoft's series of measures for innovating the
> design of the operating system kernel in the interest of thwarting the
> most common attacks that[/color]

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 12-17-2007, 04:50 AM
Alias
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft acknowledges Vista kernel elevation vulnerability

Mike Hall - MVP wrote:[color=blue]
> Its sad that there are some people who work 24/7 specifically to make
> life difficult for computer users. No matter what is created to protect
> us, some jackass is going to try to break it.
>[/color]

Ironically, Symantec made it public. A patch was released on Dec 11th so
calm down, Mike.

Alias
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 12-17-2007, 05:10 AM
Synapse Syndrome
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft acknowledges Vista kernel elevation vulnerability

"Mike Hall - MVP" <mikehall@mvps.com> wrote in message
news:ec6G2nKQIHA.1208@TK2MSFTNGP05.phx.gbl...[color=blue]
> Its sad that there are some people who work 24/7 specifically to make life
> difficult for computer users. No matter what is created to protect us,
> some jackass is going to try to break it.[/color]


So you think the security software engineers at SkyRecon Systems are
jackasses?

ss.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 12-19-2007, 11:30 AM
DarkSentinel
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft acknowledges Vista kernel elevation vulnerability

"Mike Hall - MVP" <mikehall@mvps.com> wrote in message
news:ec6G2nKQIHA.1208@TK2MSFTNGP05.phx.gbl...[color=blue]
> Its sad that there are some people who work 24/7 specifically to make life
> difficult for computer users. No matter what is created to protect us,
> some jackass is going to try to break it.[/color]

Not everyone that does that wear black hats Mike. IIRC, some companies are
hired to do exactly what these people did. Identify the processes that are
broken. I know from personal experience that sometimes a set fresh eyes is
what you need to find and fix potential problems. If the white hat guys
don't...the black hats certainly WILL.

--
Ok, I admit it, I killed Barney!!
[url]http://www.lockergnome.com/darksentinel[/url]
You know what to do with the munge


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #6 (permalink)  
Old 12-20-2007, 06:40 PM
Jupiter Jones [MVP]
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft acknowledges Vista kernel elevation vulnerability

I think his point is not that this group necessarily was doing
anything bad.
More so that resources need to be invested doing this sort of thing
because of those so intent on making computer use difficult.

If those with malicious intent stopped, computer use could be far
cheaper and easier since malware and prevention of would not be an
issue.
Resources could then be spent at nearly 100% to improving the computer
experience rather than so much just to protect from those whose
purpose is disruption.

--
Jupiter Jones [MVP]
[url]http://www3.telus.net/dandemar[/url]



"DarkSentinel" <darkmungesentinel@munge.charter.munge.net> wrote in
message news:8FFF087C-BB80-4A6C-9D7B-8BA2C842ADD9@microsoft.com...[color=blue]
> "Mike Hall - MVP" <mikehall@mvps.com> wrote in message
> news:ec6G2nKQIHA.1208@TK2MSFTNGP05.phx.gbl...[color=green]
>> Its sad that there are some people who work 24/7 specifically to
>> make life difficult for computer users. No matter what is created
>> to protect us, some jackass is going to try to break it.[/color]
>
> Not everyone that does that wear black hats Mike. IIRC, some
> companies are hired to do exactly what these people did. Identify
> the processes that are broken. I know from personal experience that
> sometimes a set fresh eyes is what you need to find and fix
> potential problems. If the white hat guys don't...the black hats
> certainly WILL.
>
> --
> Ok, I admit it, I killed Barney!!
> [url]http://www.lockergnome.com/darksentinel[/url]
> You know what to do with the munge
>
>[/color]

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #7 (permalink)  
Old 12-21-2007, 08:30 PM
DarkSentinel
Newsgroup Contributor
 
Posts: n/a
Re: Microsoft acknowledges Vista kernel elevation vulnerability

"Jupiter Jones [MVP]" <jones_jupiter@hotnomail.com> wrote in message
news:ulIizj3QIHA.1212@TK2MSFTNGP05.phx.gbl...[color=blue]
> I think his point is not that this group necessarily was doing anything
> bad.
> More so that resources need to be invested doing this sort of thing
> because of those so intent on making computer use difficult.
>
> If those with malicious intent stopped, computer use could be far cheaper
> and easier since malware and prevention of would not be an issue.
> Resources could then be spent at nearly 100% to improving the computer
> experience rather than so much just to protect from those whose purpose is
> disruption.[/color]

Oh I agree 100%. I always wonder what these people could do if they put
their minds to it. As good as I am on the hardware and network side, I'd
like to be that good on the programming side.

--
Ok, I admit it, I killed Barney!!
[url]http://www.lockergnome.com/darksentinel[/url]
You know what to do with the munge

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is Off
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Override detected UAC elevation requirement? MaW Windows Vista 2 06-21-2007 06:30 PM
ELEVATION Dave Boomhauer Windows Vista 5 02-21-2007 02:00 PM
Critical marketing vulnerability on the Vista edition comparison website James Daily Windows Vista 3 01-31-2007 07:45 AM
vulnerability vulnerability Windows XP 1 01-04-2007 03:38 AM
Vista Vulnerability in Time for Christmas--Enjoy! "It's beginnin' to look a lot like Windows!" Chad Harris Windows Vista 22 01-02-2007 11:35 AM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 07:39 PM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0