Microsoft fights "evil" kernel bug
By Stuart Turton
Posted on 11 Mar 2009 at 09:14
Microsoft's monthly patch Tuesday has brought fixes for eight vulnerabilities in Windows, including one rated critical.
The critical vulnerability is the result of "improper validation of input passed from user mode through the kernel component of the graphics device interface."
Because the flaw affects the kernel, Microsoft is warning that a successful exploit would leave an attacker with complete control of a machine.
"All that the attacker needs do is encourage a victim to view a specially formatted image and the attacker can run code on the victim's system," notes security expert Eric Schultze.
"The evil code will execute with system privileges - even if the user wasn't logged on as an administrator. With system privileges, the evil code can access, copy, or delete any files on the system, create or delete user accounts, change passwords, or install backdoors. Nasty stuff."
Elsewhere, patch MS09-008, which is rated as important, deals with four separate flaws in Windows' DNS and WNS servers.
"These vulnerabilities could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker's own systems," says Microsoft.
The third update, MS09-007, plugs a hole in the Secure Channel security package within Windows. If exploited, the flaw could let attackers impersonate an authorised user.
From around the web
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Is Microsoft mismanaging Windows on ARM?
- Dealing with spam surrogates
- Why 3G broadband can be better and cheaper than ADSL
- Is Twitter bad for business?
- Publishing your email address isn't a security disaster
- Why you'll need a fax machine to develop iOS apps
- Learning to adapt to the mobile web
- Why you shouldn't use WPS on your Wi-Fi network
- Disabled users suffer when software breaks the rules
advertisement
