Bonum Certa Men Certa

Windows Vista Left Vulnerable Over Christmas

Broken glass



AS WE POINTED OUT on Christmas day, Microsoft left its users/clients vulnerable over the holidays. But there's actually more than we mentioned at the time. One of our readers points out that new flaws were found -- accompanied by exploits -- that can hijack Windows Vista and predecessors (Vista was never secure anyway).

The following exploit utilizes the XML vulnerability in Internet Explorer to execute arbitrary code under Vista.


Here is another new one:

A vulnerability was reported in Windows Media Player. A remote user can cause arbitrary code to be executed on the target user's system.


Over at The Register, it is being reported that Samsung picture frames are dangerous to Windows users ("The disc is needed to use the kit as a USB monitor on windows XP machines"). We've covered the follies of Samsung in the past because they stabbed Linux in the back by signing a patent deal with Microsoft.

The BBC labels 2008 an unprecedentedly bad year for security, but surely it won't get any better in 2009, not when about 40% of all (Windows) machines are zombies and many people are out of work.

Criminal gangs generate so many viruses for two main reasons. Firstly, many variants of essentially the same malicious program can cause problems for anti-virus software which can only reliably defend against threats it is aware of.


Bearing in mind everything that people already know and witness, the BBC does write: "The vast majority of these malicious programs are aimed at Windows PCs. Viruses made their debut more than 20 years ago but the vast majority of that million plus total have been created in the last two-three years." It later shows the Windows logo above a caption that says "Most attacks are aimed at PCs running the Windows operating system."

Comments

Recent Techrights' Posts

As Prices Soar and Services Shut Down (Even YouTube Starts Demanding Money for the Original or a Tolerable Experience) It's Time to Explore the Real Alternatives
https://inv.nadeko.net is the most viable instance of Invidious these days
Justice Will Find Its Way at the End
We deserve an award, not SLAPP, for what we've done
March Already, Rumours of IBM Layoffs in Brazil
Red Hat might be impacted too
 
Getting Serial Sloppers to Knock the Habit of Plagiarism by LLM Slop
All in all, the fewer the slop objects, the better
Gemini Links 01/03/2025: Amends and GNU/Linux
Links for the day
Links 01/03/2025: Scam Altman's Latest Excuse, Google Price Hikes
Links for the day
Links 01/03/2025: Squashing Software Patents, USPTO Facing Additional Cuts
Links for the day
Links 01/03/2025: UNM Gopher and Getting One's Pages on gemini://
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, February 28, 2025
IRC logs for Friday, February 28, 2025
Links 28/02/2025: Mass Layoffs at Autodesk, Employee Burnout, and Measles in Texas
Links for the day
Gemini Links 28/02/2025: offpunk, Lagrange, and More
Links for the day
When the Business Goal is to Protect the Image of Criminals From the Mainstream Media or Free/Independent Press (at Any Cost)
What ever happened to the concept of "ethics" in this "legal" occupation?
Skype is Dead, Microsoft Shuts It Down in a Few Months (for Good)
Many billions down the drain
It Has Been Over a Year Since Takedown Demands From Brett Wilson LLP, Nothing Has Been Taken Down
It backfired on the Serial Defamer
Links 28/02/2025: Domestic Violence Fatalities, Escalations Again Near Taiwan
Links for the day
IBM is Trading Employees for Revenue Acquired by Buying Companies and Growing the Debt
IBM's financial plan is corporate bulimia
[Video] Full Video of Richard Stallman's Talk Earlier This Month in Italy (Nexa, Turin)
We have a collection of them
Gemini Links 28/02/2025: Spring, cgi and inetd, Gemini Protocol FAQ
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 27, 2025
IRC logs for Thursday, February 27, 2025
What the LLM Scrapers Are Doing to Tux Machines
So far today it looks like we'll have served about 1.5 million requests at midnight. That's more than 50,000 per hour or 1,000 per minute.
Netcraft's New Web Server Survey Shows Microsoft Down in Every Category
That Microsoft is still visible in
Slopwatch: Anti-Linux Garbage and Fake 'Articles' About GNU and Linux, Courtesy of Serial Sloppers and Slopfarms
Today there is a frustrating amount of FUD online that wasn't published by humans but instead generated by LLMs
Links 27/02/2025: Google Clown Computing Layoffs and Slack Goes Down as Usual
Links for the day
Links 27/02/2025: The Engagement Rehab and Another New Zine
Links for the day
Links 27/02/2025: Microsoft Trying Ads as Sales Fall, Preserving Data From Social Control Media a Real Problem
Links for the day
Hiding Crimes Against Women (i.e. Reputation Laundering) by Misusing Inapplicable Privacy Laws From Another Continent
As it turns out, "privacy" does not cover hiding illegal activities and if public information exists to prove these illegal activities, then it's perfectly OK to share it
Zurich CEO suicide, Martin Senn proximity to Adrian and Diana von Bidder-Senn, Debian
Reprinted with permission from Daniel Pocock
Debian, CentOS, RHEL source code demise now linked, accelerated after invalid trademark judgment
Reprinted with permission from Daniel Pocock
Civil Society Should Demand Removal of People Who Sought Removal of Richard Stallman
Perhaps it's noteworthy that the FSF is now being attacked (again)
RTO for You, But Not for Me: How IBM's Managers Try to Disguise Layoffs as "Resignations" or "Retirements"
What ever happened to corporate ethics?
Links 27/02/2025: Conflict Updates, Hacks Caught Red-Handed Misusing Licence to Exercise Law to Submit LLM Slop to Courts
Links for the day
Gemini Links 27/02/2025: Fuzzy Frontiers and New Arrivals at Geminispace
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 26, 2025
IRC logs for Wednesday, February 26, 2025