Researcher Finds 17 Year-Old Windows Vulnerability…in MS-DOS

MS-DOS

Guess what? A Google security researcher has uncovered a potential security vulnerability that dates all the way back to the original Windows NT released in 1993.

Security researchers—and, of course, cybercriminals, attachers, and maybe even governments—are always looking for new ways to break into Microsoft Windows, since it’s long-established itself and the lowest common denominator of operating systems. Sometimes, these research efforts uncover bugs that have been round for a long time, but Google security engineer Tavis Ormandy may have taken the cake: he found a security hole in Windows that’s so old it could be graduating from high school this year.

The bug impacts all versions of Windows from the brand-new Windows 7 all the way back to Windows NT 3.1, which originally shipped in 1993. The issue is in the Virtual DOS Machine used to support 16-bit applications originally implemented to support MS-DOS applications and 16-bit applications from Windows 3.1 days; according to Ormandy’s findings, the Virtual DOS machine can be exploited to enabled unprivileged 16-bit programs to manipulate kernel stacks so attackers could get their own code executed at system privilege levels. In theory, this could let attackers take over the computer and do anything they like. And, yes, the problem has been there for 17 years.

In a security advisory, Microsoft says it is not aware of any attacks that exploit the vulnerability, and Windows users are believed to be at low risk. However, users who are concerned can disable their system’s MSDOS and WOWEXEC subsystems (which correspond to CMDLINE and WOWCMDLINE services) to block the problem—at least, provided they don’t need to use any 16-bit applications.

Microsoft hasn’t made any statement on when it plans to release a patch; however, Microsoft is already planning on a record patch Tuesday for February 2010, with 13 security issues set to be shored up.

Trackback URL: http://www.digitaltrends.com/computing/microsoft-to-patch-17-year-old-windows-vulnerability-in-ms-dos/trackback/

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

The Comments

  1. Dave

    By: Dave
    February 5, 2010 @ 11:54 AM

    You don't keep up with news much, do you? This is already a couple weeks old news. And a fix for it will be issued this patch Tuesday.

    Reply
  

Add A Comment

If you do not have an account, click here to Register with Digital Trends or Login To Your Account.

Join The Digital Trends Community

DT RSS Feed

Everyone wants to be an insider, and you can be one too! Choose your poison: sign-up for our Newsletter, join us on Facebook, or follow us on Twitter. Do all three and you'll be swimming in the the latest news, reviews, videos and more gadget goodness!

DT Newsletter Sign-Up

Sign-up for the Digital Trends newsletter and find out about the latest contests, the hottest content, and the most popular videos. Let us keep you up-to-date!

Our Facebook

Become a DT soldier! Join us on Facebook and share the best news, guides, videos and other cool information directly with all your friends. Some might even thank you for it!

Join the thousands and follow the best of us on Facebook.

Twitter Us

Do you like information in small snippets? Then our Twitter feed is just for you. Follow Digital Trends and you'll be able to catch up daily on our latest content, or even interact directly with our team. Tweet Tweet!

Join the thousands and follow the best of us on Twitter.

That's Right, Sign-up For Our Monthly Random Prize Drawings and You Could Be That Winner.