You are here: silicon.com > Software > Malware

Malware

Vista flaw leaves OS open to DoS attack

Fix coming in next service pack?

Tags: dos, malware, flaw, os

By David Meyer

Published: 24 November 2008 09:03 GMT

A flaw has been found in Windows Vista that could allow rootkits to be hidden or denial-of-service attacks to be executed on computers using the operating system.

The vulnerability was found by Thomas Unterleitner of Austrian security company Phion, and announced on Friday. Unterleitner told silicon.com sister site ZDNet UK on Friday that Phion told Microsoft about the flaw in October but he understood a fix would only be issued in the next Vista service pack.

Security from A to Z

Click on the links below to find out more...

A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day

According to Unterleitner's disclosure of the flaw, the issue lies in the network input/output subsystem of Vista. Certain requests sent to the iphlpapi.dll API can cause a buffer overflow that corrupts the Vista kernel memory, resulting in a blue-screen-of-death crash. "This buffer overflow could [also] be exploited to inject code, hence compromising client security," Unterleitner added.

Unterleitner told ZDNet UK via email that the "exploit can be used to turn off the computer using a [denial-of-service] attack". He also suggested that, because the exploit occurs in the Netio.sys component of Vista, it may make it possible to hide rootkits.

Using a sample program, Unterleitner and his colleagues ascertained that Vista Enterprise and Vista Ultimate were definitely affected by the flaw, with other versions of Microsoft's operating system "very likely" to be affected as well. Both 32-bit and 64-bit versions are vulnerable. Windows XP is not affected.

Asked about the severity of the flaw, Unterleitner pointed out that administrative rights were needed to execute a program calling the function that would cause the buffer overflow. However, he also said it was possible - but not yet confirmed - that someone could use a malformed DCHP packet to "take advantage of the exploit without administrative rights".

"We have worked together with Microsoft Security Response Center in Redmond since October 2008 to locate, classify and fix this bug," Unterleitner wrote. "Microsoft will ship a fix for this exploit with the next Vista service pack."

Microsoft told ZDNet UK on Friday that it had investigated the issue but was "currently unaware of any attacks trying to use the vulnerability or of customer impact". It could not, however, confirm the inclusion of a fix for the problem in the as-yet-unreleased second service pack for Vista, nor give the release date for that service pack.

Original article: Kernel vulnerability found in Windows Vista from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
1 x 1st/ 2nd line support analsyt (18,000- 24,000) North East London

1 x 1st/ 2nd line support analsyt (18,000- 24,000) > MCSE and MCP (ideally in Windows Vista) qualified within the last 2 years > 2 years 1st and 2nd ...

PHP DEVELOPER - GLOBAL TELECOMS COMPANY - CAMBRIDGE

You will be working with the Applications Manager to gather requirements, delivery web applications and bug fix existing applications. PHP, AJAX, ...

Cisco & Linux Developer, London

Or any other language as long as the output does not have further dependencies on the target platform to run the automation program (windows without ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: