Skip to main content

Proof-of-Concept Security Flaw Hits Vista

It may not present much—or, at the moment, any—danger in the real world, but a proof-of-concept security flaw outlined by a Russian research firm seems likely to go down in the books as the first security issue uncovered in Microsoft’s Windows Vista operating system.

The issue in Microsoft’s MessageBox API which targets a flaw in Windows’ Client Server Run-Time Subsystem. The issue is not Vista-specific; it impacts Windows XP, Windows 2003, and Windows 2000, and, in theory, could enable an attacker who already has authenticated access to a system to escalate privileges, potentially taking over the machine.

Microsoft says that they are not aware of any exploits of the flaw having been found in the wild, and users’ overall vulnerability is quite low. F-Secure’s Mikko Hypponen has told the Associated Press that the exploit could not be used to write a worm or create tools which could take over a Vista system remotely: the exploit would require local access to the computer, probably by tricking a user into running a trojan horse on their system.

Windows Vista is currently only available to Microsoft’s business customers and volume licensees; both Windows Vista and Office 2007 will go on sale to consumers at the end of January 2007. Microsoft is reportedly targeting January 30th as the products’ launch dates, following a media event in New York January 29th.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
AMD and Apple face a dangerous new security flaw
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

Researchers from cybersecurity firm Trail of Bits just found a vulnerability that affects some of the biggest brands in tech, namely Apple, AMD, and Qualcomm. The vulnerability, dubbed LeftoverLocals, affects graphics cards made by those companies. That makes it pretty widespread, with it affecting devices ranging from PCs and servers to tablets and smartphones. This flaw, if exploited, could allow attackers to access and steal data from vulnerable devices.

Normally, when working in a shared environment -- such as a workstation or a cloud computing infrastructure -- each user only has access to their own data and resources, even when working on the same hardware. However, LeftoverLocals bypasses these security measures and uses GPU memory to let potential attackers steal data from the other users on that same hardware.

Read more
Dell just hit reset on the XPS
The XPS 14 and 16 in front of a window.

Goodbye, XPS 15 and XPS 17. It was nice knowing ya.

Just in time for 2024 and CES about to hit, Dell has unveiled a massive change to its XPS line of laptops, which involves swapping out the XPS 15 and 17 with a new XPS 14 and 16 while also completely redesigning the laptops around the divisive features straight from the (now defunct) XPS 13 Plus.

Read more
Windows may have a serious security problem on its hands
A finger pressing on a fingerprint reader on a laptop.

The premier sensors enabling Windows Hello fingerprint authentication are not as secure as manufacturers had hoped. Researchers have discovered security flaws in a number of fingerprint sensors used in several laptops that work with the Windows Hello authentication feature.

Security researchers at Blackwing Intelligence have uncovered that laptops made by Dell, Lenovo, and Microsoft can have their Windows Hello fingerprint authentication bypassed easily due to vulnerabilities in the sensors that can cause them to be taken over by bad actors at the system level.

Read more