ZDNet UK


Skip to Main Content

  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Videos
  6. Jobs
  7. Resources
  8. Community

 

ZDNet UK RSS Feeds


Security threats Toolkit

Kernel vulnerability found in Windows Vista

David Meyer ZDNet.co.uk

Published: 21 Nov 2008 16:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw has been found in Windows Vista that could allow rootkits to be hidden or denial-of-service attacks to be executed on computers using the operating system.

The vulnerability was found by Thomas Unterleitner of Austrian security company Phion, and announced on Friday. Unterleitner told ZDNet UK on Friday that Phion told Microsoft about the flaw in October, but he understood that a fix would only be issued in the next Vista service pack.

According to Unterleitner's disclosure of the flaw, the issue lies in the network input/output subsystem of Vista. Certain requests sent to the iphlpapi.dll API can cause a buffer overflow that corrupts the Vista kernel memory, resulting in a blue-screen-of-death crash. "This buffer overflow could [also] be exploited to inject code, hence compromising client security," Unterleitner added.

Unterleitner told ZDNet UK via email that the "exploit can be used to turn off the computer using a [denial-of-service] attack". He also suggested that, because the exploit occurs in the Netio.sys component of Vista, it may make it possible to hide rootkits.

Using a sample program, Unterleitner and his colleagues ascertained that Vista Enterprise and Vista Ultimate were definitely affected by the flaw, with other versions of Microsoft's operating system "very likely" to be affected as well. Both 32-bit and 64-bit versions are vulnerable. Windows XP is not affected.

Read this

Feature
Protect your mobile devices in any location

Forget the recent hype about about Chinese hackers — users and organisations should be securing mobile systems as a matter of course, so follow these tips to find out how

Read more +

Asked about the severity of the flaw, Unterleitner pointed out that administrative rights were needed to execute a program calling the function that would cause the buffer overflow. However, he also said it was possible — but not yet confirmed — that someone could use a malformed DCHP packet to "take advantage of the exploit without administrative rights".

"We have worked together with Microsoft Security Response Center in Redmond since October 2008 to locate, classify and fix this bug," Unterleitner wrote. "Microsoft will ship a fix for this exploit with the next Vista service pack."

Microsoft told ZDNet UK on Friday that it had investigated the issue, but was "currently unaware of any attacks trying to use the vulnerability or of customer impact". It could not, however, confirm the inclusion of a fix for the problem in the as-yet-unreleased second service pack for Vista, nor give the release date for that service pack.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
16 out of 16 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Latest Video

Win a Yoggie Gatekeeper Card Pro and Compaq notebook

Win a Yoggie Gatekeeper Card Pro and Compaq notebook

How many security software applications are found in a Gatekeeper Card Pro?

Competition closes - 22 Jan 2009

Sentry Posts Blog

EC smartcard cartel raid companies nam...

The semiconductor companies raided by European Commission anti-competition inspectors in October were STMicroelectronics, NXP, Infineon, and Renesas, according to a Reuters article. Inspectors... More

Post a comment

Mobile Security and the MD5 Hack: Day...

Mobile Security and the MD5 Hack: Day Trading By Mobile Beware Author: Eric Everson, Founder MyMobiSafe.com It seems that we can do as much or more from our phones today than we... More

Post a comment

AT&T and TMobile: The New Era of Mobil...

AT&T and TMobile: The New Era of Mobile Security Complexity Author: Eric Everson, Founder MyMobiSafe.com It has been just days since AT&T and TMobile have been issued steep fines... More

Post a comment