Windows Vista
Windows Vista
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Hacker highlights gaping Vista security hole

Microsoft tries to play it down

Ian Williams, vnunet.com 16 Feb 2007
ADVERTISEMENT

White hat hacker Joanna Rutkowska claims to have discovered a gaping hole in the User Account Control (UAC) security functionality of Windows Vista.

Microsoft admitted that many users ran Windows XP constantly using the admin account, which provides unfettered access to all parts of the system.

To help mitigate the security risks, Vista runs in a normal user account by default and provides pop-up confirmation dialogues when it needs to perform admin functions, such as modifying system files.

Rutkowska discovered that when Vista detects that the user is running an installation file it kicks into full admin mode.

If a user wishes to install a new program they are presented with the option either to allow the installer complete system privileges or not to run the program at all.

Rutkowska wrote on her Invisible Things blog: "That means that if you downloaded some freeware Tetris game, you will have to run its installer as administrator, giving it full access to all your file system and registry, and allowing it to load kernel drivers! Why should a Tetris installer be allowed to load kernel drivers?

"I would like to be offered a choice whether to fully trust a given installer executable (and run it as full administrator) or just allow it to add a folder in C:\Program Files and some keys under HKLM\Software and do nothing more.

"I could do that under Windows XP, but apparently I can't under Vista, which is a bit disturbing."

A few days after her posting there was a lengthy and detailed response from Mark Russinovich, a Technical Fellow at Microsoft.

Russinovich essentially admitted that, while the problem exists, it was a design choice that stemmed from the balance between security and usability.

"Because elevations and integrity levels do not define a security boundary, potential avenues of attack, regardless of ease or scope, are not security bugs, " he said.

In light of the huge security campaign surrounding Windows Vista in 2006, Rutkowska said in a follow up posting that this explanation simply is not good enough and that Microsoft should attempt to solve the problem rather than try and dismiss the issue.


All Operating Systems

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities