Friday, November 28, 2008

Vista kernel is vulnerable oh my


Vista kernel is vulnerable

Vista kernel is vulnerable


By Egan Orion
Nov 25, 2008 9:55 AM
Tags: Vista | kernel | vulnerable | Windows | Microsoft
A flaw has been discovered in Microsoft's flagship Windows Vista operating system, but the company has said it won't fix the glitch until its next, as-yet unannounced, service pack.

Discovered by Austrian researcher Thomas Unterleitner of the insecurity company Phion and announced last Friday, the buffer overflow flaw reportedly exists in Vista's networking I/O subsystem.

It can cause a blue screen of death system crash, allow denial of service attacks, or enable injection of rootkits or other malware such as viruses, trojans, bots or keyloggers.

Unterleitner told ZDnet UK that Phion had notified Microsoft of the vulnerability in October.

Phion successfully tested an exploit of the vulnerability against Vista Enterprise and Vista Ultimate and believes that other versions of Windows Vista are "very likely" also vulnerable. It says that both 32-bit and 64-bit versions of the operating system contain the flawed code.

Windows XP reportedly doesn't contain the vulnerability.

-----------------------------------------------------------
See story here