Skip to main content

Proof-of-Concept Security Flaw Hits Vista

It may not present much—or, at the moment, any—danger in the real world, but a proof-of-concept security flaw outlined by a Russian research firm seems likely to go down in the books as the first security issue uncovered in Microsoft’s Windows Vista operating system.

The issue in Microsoft’s MessageBox API which targets a flaw in Windows’ Client Server Run-Time Subsystem. The issue is not Vista-specific; it impacts Windows XP, Windows 2003, and Windows 2000, and, in theory, could enable an attacker who already has authenticated access to a system to escalate privileges, potentially taking over the machine.

Microsoft says that they are not aware of any exploits of the flaw having been found in the wild, and users’ overall vulnerability is quite low. F-Secure’s Mikko Hypponen has told the Associated Press that the exploit could not be used to write a worm or create tools which could take over a Vista system remotely: the exploit would require local access to the computer, probably by tricking a user into running a trojan horse on their system.

Windows Vista is currently only available to Microsoft’s business customers and volume licensees; both Windows Vista and Office 2007 will go on sale to consumers at the end of January 2007. Microsoft is reportedly targeting January 30th as the products’ launch dates, following a media event in New York January 29th.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Windows may have a serious security problem on its hands
A finger pressing on a fingerprint reader on a laptop.

The premier sensors enabling Windows Hello fingerprint authentication are not as secure as manufacturers had hoped. Researchers have discovered security flaws in a number of fingerprint sensors used in several laptops that work with the Windows Hello authentication feature.

Security researchers at Blackwing Intelligence have uncovered that laptops made by Dell, Lenovo, and Microsoft can have their Windows Hello fingerprint authentication bypassed easily due to vulnerabilities in the sensors that can cause them to be taken over by bad actors at the system level.

Read more
Western Digital responds to claims that SanDisk SSD failures have design flaw
Sandisk Extreme Pro SSD.

There is now a possible explanation behind the SanDisk SSD failures that have been an ongoing issue throughout most of 2023. The issue first gained notice on Reddit as users complained of failing SSDs and the loss of data.

The problem gained more attention when SanDisk's parent company, Western Digital, became subject to several class-action lawsuits in August, according to Ars Technica.

Read more
Here’s more proof that Apple is wrong about MacBook memory
The keyboard and trackpad of the MacBook Pro.

Apple has made some big claims about its unified memory over the past few years. That was made explicit this week when an Apple representative was asked why it has begun to sell an 8GB starting configuration of its new M3 Pro MacBook Pro, a laptop that's already been under scrutiny recently. The interviewee responded by saying that 8GB on a MacBook was equivalent to 16GB on a comparable system. But is that really true? It's been hard to test so far, but a recent video posted by Max Tech suggests that in practice, at least, it's not so simple.

M3 MacBook Pro 8GB vs 16GB RAM - How BAD is base model?

Read more