Skip to navigation
Latest News

Microsoft: Zero-day Windows flaw not serious

bug

By Nicole Kobie

Posted on 11 Aug 2010 at 12:18

The latest zero-day flaw to hit Windows isn't likely to be a major security concern, according to Microsoft.

The flaw in Windows Kernel-mode drivers (win32k.sys) affects all supported versions of Microsoft's OS, taking advantage of buffer overflow problems that happen when copying bitmap files from the clipboard.

"We are not aware of attacks that try to use the reported vulnerability or of any customer impact at this time," said security communications manager Jerry Bryant in a post in the Microsoft blog.

Bryant said the attack only allows for local elevation of privileges.

"For this issue to be exploited, an attacker must have valid log-on credentials on the target system and be able to log on locally, or must already have code running on the target system," he said. "The vulnerability cannot be exploited remotely, or by anonymous users."

Some security firms had initially said the flaw could be used to attack systems, with Vupen Security claiming it could be used to cause a denial of service attack. Secunia said the flaw could be "exploited by malicious users to crash an affected system or potentially execute arbitrary code with kernel privileges."

But Gil Dabah, a security researcher who goes by the name Arkon and who originally uncovered the vulnerability, said any attack would be difficult. "It’s very hard to exploit it for code execution, on the edge of impossible," the researcher noted in a blog post. "That’s why I felt safe about releasing it publicly."

Microsoft said it would include a fix in a future security update, but didn't say if it would arrive next month. The software giant yesterday issued patches for a record number of flaws as part of its monthly security update.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

User comments

Only local?

The definition of a local only attack presumes the attacker "has" to be sat at the pysical machine.

It looks to me like this _could_ be remotely triggered if a remote user has access to the system. Through say Adobe reader.

Just because an attack does not yet exist, does not mean one will not be written.

By reashlin on 11 Aug 2010

Leave a comment

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.