EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.12.09

Vista 7 Exploit is Out (Zero-Day Vulnerability)

Posted in Microsoft, Security, Servers, Vista 7, Windows at 12:11 pm by Dr. Roy Schestowitz

Vista 7

Summary: Vista 7 and Server 2008 R2 both suffer from a zero-day hole and there is no solution to it yet

VISTA 7 was never a secure operating system, not even when it was in beta. To give a sample of posts on that matter:

The reality of this matter is that Vista 7, as expected, has a very major new flaw, which is already being exploited

This bug is a real proof that SDL #FAIL
The bug trigger an infinite loop on smb{1,2}, pre-auth, no credential needed…
Can be trigered outside the lan via (IE*)

It sure sounds familiar and Microsoft does no deny it.

Microsoft probing Windows 7 zero-day hole

Microsoft said on Wednesday it is looking into a report of a vulnerability in Windows 7 and Server 2008 Release 2 that could be used by an attacker to remotely crash the computer.

[...]

Gaffié also posted proof-of-concept code for the “Windows 7, Server 2008R2 Remote Kernel Crash.”

“It is an error in the SMB protocol,” tells one person, “and it sends the machine into an infinite loop. Power cycle or reset time it is.”

A reader of ours asks: “Isn’t this a repeat of the teardrops-like exploit from this summer / fall?

“If so, then the reporters seem to think they can get away with [fooling] the public as to how long Microsoft is taking to patch their problems.”

Update: The Windows kernel has just had critical holes addressed, but the above remains unpatched.

Microsoft on Tuesday issued six security bulletins fixing 15 vulnerabilities, including a critical patch for holes in the Windows kernel and other Windows and Office components that could allow an attacker to take control of a computer.

One of our readers was unable to find out if the RBS disaster has Windows to blame. It’s too secretive.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Another Misleading Article Regarding Patents From Rana Foroohar at the Financial Times

    In an effort to promote the agenda of patent maximalists, many of whom are connected to the Financial Times, another deceiving report comes out



  2. Monika Ermert's Reports About the Crisis at the EPO and IP Kat's Uncharacteristically Shallow Coverage

    News from inside the Council shows conflict regarding the quality of European Patents (granted by the EPO under pressure from top-level management)



  3. Patent Troll VirnetX a Reminder to Apple That Software Patents Are a Threat to Apple Too

    VirnetX, a notorious patent troll, is poised to receive a huge sum of money from Apple and Qualcomm is trying to ban Apple products, serving to remind Apple of the detrimental impact of patents on Apple itself



  4. Links 16/10/2017: Linux 4.14 RC5, Debian 9.2.1, End of LibreOffice Conference 2017

    Links for the day



  5. The Systematic Erosion of Workers' Rights and Holidays at the EPO Goes Years Back

    The legitimacy of the staff's concerns at the EPO, having seen basic labour safeguards being shredded to pieces by Battistelli for a number of years (predating even the escalation of the conflict)



  6. Articles in English and German Speak About the Decline in Quality of European Patents (Granted by the EPO)

    Heise and The Register, two sites that have closely watched EPO affairs for a number of years, speak about the real problem which is declining patent quality (or rushed examination) -- a recipe for frivolous litigation in Europe



  7. Software Patents and Patent Trolls Not a Solved Issue, But the US is Getting There

    A media survey regarding software patents, which are being rejected in the US in spite of all the spin from law firms and bullies such as IBM



  8. US Patent Trolls Are Leaving and the Eastern District of Texas Sees Patent Cases Falling by More Than Half

    The decline of patent aggression in the US and the patent microcosm's response to Justices, having ruled in TC Heartland, curtailing patent trolls



  9. Qualcomm's Nightmares Are Getting Worse as Antitrust Questions Are Raised and Assessed

    Qualcomm is getting itself deeper in trouble as fines pile up and its multi-billion dollar dispute with Apple isn't getting it anywhere



  10. Forget About Apple; Two of the Leading Phone Makers (Samsung and Huawei) Are Bickering Over Patents

    Massive Android OEMs, Huawei and Samsung, are in a big patent dispute and this time, for a change, China is a legal battleground



  11. Tim Heberden From the Glasshouse Advisory is Throwing Stones in a Glasshouse to Create Patent Litigation

    IAM's latest lobbying, aided by the patent microcosm, for a climate of feuds and disputes (to line the pockets of the litigation 'industry')



  12. Access to Medicine is More Important Than Patents

    Some of the latest news about patents that impede/deny access to crucial medication; strategic litigation from the generics sector, seeking to invalidate patents and then offer low-cost alternatives



  13. Links 14/10/2017: Windows Breaks Dutch Law, Wine 2.19 Released

    Links for the day



  14. The Patent Trial and Appeal Board (PTAB) Supported by Congress, a Federal Judge, Soon to be Supported by the Supreme Court Too?

    The Patent Trial and Appeal Board is still widely defended, except by the patent microcosm which likes (and profits from) patent trolls and litigation Armageddon



  15. Patents Are Turning BlackBerry and Nokia, Which Used Android, Into Anti-Android Fronts That Tax Android OEMs

    The Canadian BlackBerry has sued BLU in the US only to compel it to pay 'protection' money; Nokia's patents are being scattered to trolls, which are doing something similar (without risking litigation themselves)



  16. The Unified Patent Court (UPC) is Rotting Like the European Patent Office

    The Unitary Patent litigation pipe dreams (or prosecution/trolling fast lane), which Battistelli's EPO long relied on, turn out to be the road to nowhere



  17. Lying and Faking Now a Standard Procedure at the European Patent Office

    The European Patent Organisation (EPO) under the leadership (or chairmanship) of Christoph Ernst continues to relay lies from Battistelli's Office, SUEPO rejects these, the Office lies about SMEs, prioritises Microsoft (again), and probably buys fake Twitter "followers"



  18. Links 13/10/2017: X.Org Server 1.19.5, pfSense 2.4, Final Stages of Ubuntu 17.10

    Links for the day



  19. Truly Terrible 'Journalism' About António Campinos Boils Down to Lobbying and Agenda-Pushing

    The expectedly shallow coverage of the appointment (succession) of Battistelli's French pick, which will likely change nothing of significance at the European Patent Office (EPO)



  20. Under Christoph Ernst, the Council is Just a Megaphone of Battistelli's EPO, Including on Patent Quality

    The Administrative Council of the EPO does not appear to be interested in a serious, adult, scientific debate about the quality of European Patents (EPs) and is instead relaying lies from Benoît Battistelli



  21. Links 12/10/2017: Cutelyst 1.9.0, Qt Creator 4.5 Beta

    Links for the day



  22. The Hogwash Begins: Patent Microcosm's Media Pretends Campinos is Anything But Battistelli's French Succession Plan

    A survey of media coverage regarding António Campinos, the French person whom Benoît Battistelli selected as his successor at the EPO



  23. Patent Quality at the EPO (European Patents) is Slipping While Battistelli's Office Boasts “Expansion of Early Certainty” (Even Worse)

    The EPO is staring down the abyss as high-level EPO management, quite frankly as usual, looks for new ways to further exacerbate patent quality (for superficial gains in the number of granted patents) rather than improve it



  24. Former Microsoft Employee Explains Why Microsoft 'Embrace' of GNU/Linux and Free/Libre Open Source Software is Like W3C Entryism

    Microsoft's latest moves are "EEE" that "concern" him, according to this new video



  25. Links 11/10/2017: Krita 3.3.1, KDE Plasma 5.12 Plans

    Links for the day



  26. China is Getting Full of -- and Fed Up With -- Patent Trolls

    In China too, as expected, local companies are becoming rather disgusted by a wave of patent trolls, enabled by misguided officials and bad advice from the likes of IAM (which sets up events in China at the behest of the patent microcosm)



  27. The FRAND Lobby is Trying to Sneak Software Patents Into Countries That Banned Them

    The patent lobby is attempting to find new ways to impose patents on software (with euphemisms like "reasonable", "non-discriminatory" or "fair"), even in places that explicitly disallow these



  28. Musical Chairs as Battistelli's 'Chinchilla' García-Escudero Márquez Could Reportedly Take António Campinos' Place

    A culture of nepotism continues to thrive at the EPO, with García-Escudero Márquez rumoured to be after Campinos' position now that he's taking Battistelli's position; García-Escudero Márquez is also Battistelli's 'chinchilla' at the appeal boards, obliterating any illusion of independence



  29. With Surveillance Recruits at the EPO, Are (or Were) DNA Tests Ever on the Agenda?

    Since a lot of what's happening at WIPO has also happened at the EPO, and overlap between the two is growing, we recall tactics which are illegal but are miraculously protected by the veil of immunity



  30. Links 10/10/2017: Plasma 5.11, GCC 5.5 Released

    Links for the day


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts