Eye on Security: Vista 7 is 'Secure', They Promised
- Dr. Roy Schestowitz
- 2010-11-30 21:34:07 UTC
- Modified: 2010-11-30 21:34:07 UTC
Summary: Vista 7 -- just like Vista and its processors -- is still Swiss cheese based on the latest news
●
Breaking That Other OS
Yet another means of exploiting that other OS has been demonstrated by Sophos. An ordinary user can gain complete control of the system whether it is XP, Vista, “7ââ¬Â³ etc. simply by running some code that tweaks a key in the registry. A workaround is to create a new key to block users from changing keys in the registry… Duh… How’s that for backwards compatibility?
This is another demonstration that M$ has created a monster running on nearly every PC on the planet that invites compromise. Now, hundreds of millions of users will have to do some dance with updates or tweak the registry themselves to do something that M$ neglected to do many years ago.
●
'Nightmare' kernel bug lets attackers evade Windows UAC security
Microsoft is investigating reports of an unpatched vulnerability in the Windows kernel that could be used by attackers to sidestep an important operating system security measure.
One security firm dubbed the bug a potential "nightmare," but Microsoft downplayed the threat by reminding users that hackers would need a second exploit to launch remote attacks.
●
Newly discovered Windows kernel flaw bypasses UAC
Last week an exploit for a Windows kernel flaw was published by an unknown source. Presumably as a joke, details of the flaw, along with proof-of-concept code, were published on Code Project. Code Project is a programmer peer support community, containing many tutorials and useful snippets of code to assist developers. Malware developers are not the usual target audience for posts made to the site, and so perhaps unsurprisingly, the article has been removed (though is mirrored here).
The flaw is a privilege escalation vulnerability. Anyone who can run code on a Windows system can elevate her privileges to the highest level, and accordingly install back doors, compromise sensitive data, and so on. The flaw lies in a critical Windows driver called win32k.sys. The driver inappropriately handles certain data stored in the registry—data that is stored on a per-user basis, and hence accessible to any unprivileged program. The proof-of-concept code uses this flaw to elevate the privileges of the user running the demo code; it could just as well be used to install a back door or other malware.
Recent Techrights' Posts
- GNOME Foundation's Microsoft Developer Account
- "Lately they're teaming up with Mozilla to eliminate middle click paste - something which I use continuously."
- Links 10/01/2026: "Abolish ICE or GTFO", Calls to Ban X/Twitter From Apple/Google App Stores (or Implement National Blocks) Over MElon Turning It Into Non-consensual Deepfake Porn Site
- Links for the day
- EPO People Power - Part XXX - New Year Starts, Cocainegate Still Discussed a Lot, António Campinos Desperate for Distraction From It
- Why the sudden change or 'generosity'? [...] Actual cocaine addicts caused nervous breakdowns among sober people
- IBM and Microsoft Hiding Layoffs in Similar, Overlapping Ways
- Performance Improvement Plans aplenty
- IBM is a Cancer That Attaches Itself to Everything
- Red Hat should have remained an independent company
-
- Monday, January 12, Red Hat Layoffs Allegedly Planned
- We'll update this post or follow up if or when we get more information
- Slop Still Becoming Rare as Another Week Ends
- Generally speaking, calm and quiet is desirable, it's what we hope for (an absence of slop, a lack of need to keep abreast of it, ultimately)
- Links 10/01/2026: Iran Offline, Venezuelans Decry Civilian Casualties
- Links for the day
- GAFAM Wants War
- Go war! Go bailouts! Go debt! Go Wall Street!
- GNU/Linux and Chromebooks Rose to Almost 10% in Haiti
- What's noteworthy is that this month GNU/Linux is measured at around 8% and ChromeOS at about 2%
- 2026 Might be the Year Microsoft Replaces Layoffs With Mass Firings (No Severance Payments to Dismissed Staff)
- It's hard to "see" PIPs unless insiders blow the whistle
- Links 10/01/2026: STV Layoffs (Scottish TV), “CBS Evening News” in Chaos (Culls and Censorship by the US Regime)
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, January 09, 2026
- IRC logs for Friday, January 09, 2026
- Gemini Links 10/01/2026: Blackout, E-Waste, and Secondary Smartphone
- Links for the day
- Plot Twist: Microsoft MSN Relays Articles Hinting at or Pointing to Mass Layoffs Soon, Other Gossip
- the narrative from Microsoft's "PR bunny" (Shaw) is showing mold already
- Links 09/01/2026: Google and Character.AI Implicitly Accept Chatbots Kill Kids and GLP-1 ‘Slimming Pens’ Turn Out to be a Lot Worse Than Advertised
- Links for the day
- 'Vibe Coding' is Not "AI", It's a Sewer, It is Junk
- Linus Torvalds was wrong. 'Vibe coding' isn't good for anything.
- GNU/Linux May be Approaching 10% "Market Share" in Montenegro
- The surge started around 2021
- At IBM, "Employee Reviews" (or Appraisals in the UK) Are a "Trojan Horse" for RAs (Mass Layoffs), a Waste of Time
- comments from IBMer serve to suggest that appraisals can be precursors
- Links 09/01/2026: Technical Blogging Lessons Learned and Google's Gmail Getting a Lot Worse
- Links for the day
- More IBM Layoffs in India
- If IBM cannot afford to retain workers in India, then something is truly "out of control" at IBM
- Escaping GAFAM Colonialism Requires Homegrown Free Software
- GNU/Linux now measured at 3% in Zambia
- Dr. Richard Stallman Has Done No Harm to the GNU Project or the FSF (He Had Benefited Both, Always, Even After the Attacks on Him Began)
- Some people try to prevent Dr. Stallman from speaking or having a platform where many people can hear him
- GNU/Linux at 4% in Saudi Arabia, Says statCounter
- Some years ago Windows fell to a "market share" of just 11% there
- Microsoft Isn't Denying the Mass Layoffs
- Still silence from Microsoft
- In Western Africa GNU/Linux Flirts With 5% Market Share
- there's a gradual increase in GNU/Linux usage there
- Gemini Links 09/01/2026: Pro1 X Repair and the Mercury Protocol
- Links for the day
- Links 09/01/2026: Cambodia and China Extradition, "NATO’s High-risk Patrols Near Ukraine"
- Links for the day
- No, Microsoft Did Not Deny the Q1 Mass Layoffs (Microsoft Can Delay These)
- Maybe they disperse or delay the layoffs (changing plans), but the layoffs are going to happen
- Only One Person in Charge of Fedora is Not IBM Staff
- This is not a community project, it's just a way for IBM to onboard unpaid volunteers
- This Is Not a Drill, GNU/Linux is Really Going 'Mainstream' on Laptops (and Desktops)
- It is important to explain to people software freedom
- IBM Albany Layoffs
- not only did many in the site lose their job; there's more to come "and likely another one in February" (weeks from now)
- EPO Workers' Industrial Action to Include Many Strikes, to Last Several Months
- In some ways, The Hague and Bavaria are becoming almost indistinguishable from Moscow
- EPO People Power - Part XXIX - Getting DER SPIEGEL, FAZ, Deutschlandfunk and Sueddeutsche Zeitung (SZ) to Cover EPO Scandals
- We kindly ask our readers to contact their local media and urge it to cover the scandals
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, January 08, 2026
- IRC logs for Thursday, January 08, 2026
- Gemini Links 08/01/2026: "New Year, Old Plans" and Alex's "Butlerian Jihad"
- Links for the day
- LLM Slop About "Linux" Scarce and of Very Low Quality
- At this rate, we reckon there may be one (or zero) per day by year's end
- IBM's "Forever Layoffs" (to Bypass Warnings or Notices as Required by WARN Act)
- There is a bunch of speculations about when the next "major round" of RAs will be
- Attempts to Undermine This Site's Latest Series Using Intimidation, Threats, and Presumptuous Accusations
- threatening language is less effective when everyone is an alibi
- Links 08/01/2026: "Golden Smartphone" Scam and Riseup Account Issues
- Links for the day
- Links 08/01/2026: Possible "Collapse of NATO Over Greenland"; Journalistic Malpractice and "US Voters Hate Slop"
- Links for the day
- EPO People Power - Part XXVIII - A Sensitive Issue for Germany and The Netherlands
- If Germans who read this series can communicate this to public officials or to their media, maybe they can strike a nerve and get the ball rolling
- Age Discrimination at IBM Discussed Amid Mass Layoffs (Especially in the United States)
- Workers are anxious. Are they next to face the axe?
- Gemini Links 08/01/2026: Potentiometer Calculator, Power Outages, Why You Should Abandon Discord for IRC (e.g. Ergo), and Formatting Gopher Posts
- Links for the day
- Links 08/01/2026: More Software Patents Squashed, White House Repeats Misinformation From the Kremlin
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, January 07, 2026
- IRC logs for Wednesday, January 07, 2026