Skip to main content

Proof-of-Concept Security Flaw Hits Vista

It may not present much—or, at the moment, any—danger in the real world, but a proof-of-concept security flaw outlined by a Russian research firm seems likely to go down in the books as the first security issue uncovered in Microsoft’s Windows Vista operating system.

The issue in Microsoft’s MessageBox API which targets a flaw in Windows’ Client Server Run-Time Subsystem. The issue is not Vista-specific; it impacts Windows XP, Windows 2003, and Windows 2000, and, in theory, could enable an attacker who already has authenticated access to a system to escalate privileges, potentially taking over the machine.

Microsoft says that they are not aware of any exploits of the flaw having been found in the wild, and users’ overall vulnerability is quite low. F-Secure’s Mikko Hypponen has told the Associated Press that the exploit could not be used to write a worm or create tools which could take over a Vista system remotely: the exploit would require local access to the computer, probably by tricking a user into running a trojan horse on their system.

Windows Vista is currently only available to Microsoft’s business customers and volume licensees; both Windows Vista and Office 2007 will go on sale to consumers at the end of January 2007. Microsoft is reportedly targeting January 30th as the products’ launch dates, following a media event in New York January 29th.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
How to access the dark web safely and securely
1148276 autosave v1 tor dark web private browsing security

While accessing the dark web isn't necessarily wrong or illegal, it's important to know how to navigate this part of the internet safely. Accessing the dark web isn't like surfing the web everywhere else online. You need to take precautions.

In this guide, we'll show you what you need to know about how to access the dark web and how to keep yourself safe while you use it.

Read more
AMD and Apple face a dangerous new security flaw
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

Researchers from cybersecurity firm Trail of Bits just found a vulnerability that affects some of the biggest brands in tech, namely Apple, AMD, and Qualcomm. The vulnerability, dubbed LeftoverLocals, affects graphics cards made by those companies. That makes it pretty widespread, with it affecting devices ranging from PCs and servers to tablets and smartphones. This flaw, if exploited, could allow attackers to access and steal data from vulnerable devices.

Normally, when working in a shared environment -- such as a workstation or a cloud computing infrastructure -- each user only has access to their own data and resources, even when working on the same hardware. However, LeftoverLocals bypasses these security measures and uses GPU memory to let potential attackers steal data from the other users on that same hardware.

Read more
Dell just hit reset on the XPS
The XPS 14 and 16 in front of a window.

Goodbye, XPS 15 and XPS 17. It was nice knowing ya.

Just in time for 2024 and CES about to hit, Dell has unveiled a massive change to its XPS line of laptops, which involves swapping out the XPS 15 and 17 with a new XPS 14 and 16 while also completely redesigning the laptops around the divisive features straight from the (now defunct) XPS 13 Plus.

Read more