Eye on Security: Vista 7 is 'Secure', They Promised
- Dr. Roy Schestowitz
- 2010-11-30 21:34:07 UTC
- Modified: 2010-11-30 21:34:07 UTC
Summary: Vista 7 -- just like Vista and its processors -- is still Swiss cheese based on the latest news
●
Breaking That Other OS
Yet another means of exploiting that other OS has been demonstrated by Sophos. An ordinary user can gain complete control of the system whether it is XP, Vista, “7ââ¬Â³ etc. simply by running some code that tweaks a key in the registry. A workaround is to create a new key to block users from changing keys in the registry… Duh… How’s that for backwards compatibility?
This is another demonstration that M$ has created a monster running on nearly every PC on the planet that invites compromise. Now, hundreds of millions of users will have to do some dance with updates or tweak the registry themselves to do something that M$ neglected to do many years ago.
●
'Nightmare' kernel bug lets attackers evade Windows UAC security
Microsoft is investigating reports of an unpatched vulnerability in the Windows kernel that could be used by attackers to sidestep an important operating system security measure.
One security firm dubbed the bug a potential "nightmare," but Microsoft downplayed the threat by reminding users that hackers would need a second exploit to launch remote attacks.
●
Newly discovered Windows kernel flaw bypasses UAC
Last week an exploit for a Windows kernel flaw was published by an unknown source. Presumably as a joke, details of the flaw, along with proof-of-concept code, were published on Code Project. Code Project is a programmer peer support community, containing many tutorials and useful snippets of code to assist developers. Malware developers are not the usual target audience for posts made to the site, and so perhaps unsurprisingly, the article has been removed (though is mirrored here).
The flaw is a privilege escalation vulnerability. Anyone who can run code on a Windows system can elevate her privileges to the highest level, and accordingly install back doors, compromise sensitive data, and so on. The flaw lies in a critical Windows driver called win32k.sys. The driver inappropriately handles certain data stored in the registry—data that is stored on a per-user basis, and hence accessible to any unprivileged program. The proof-of-concept code uses this flaw to elevate the privileges of the user running the demo code; it could just as well be used to install a back door or other malware.
Recent Techrights' Posts
- SLAPP Censorship - Part 58 Out of 200: 5RB and Brett Wilson LLP Helped Garrett and Graveley Make Equivalent of GAFAM NDAs Superficially 'Enforceable' in the UK, Using Threats
- laziness results in many hours and high lawyers' fees
-
- Red Hat Circling Down the Slop Drain
- IBM, governed by slop fanatics, is going to do a lot of damage
- Slop is an Addiction, Its Users Find It Addictive
- please do not tolerate people who slop
- The Corrupt Lecture the Non-Corrupt - Part VII - Secrecy at the EPO (Regarding Cocaine and Nepotism) Has Undermined Trust in Management
- If Europe's second-largest institution is run by the "Alicante Mafia", does this mean that other key European institutions are "Mafia"?
- SLAPP Censorship - Part 59 Out of 200: Mentioning the Fact Alex Graveley Arrested and Charged for Strangulation in Texas is "Reckless" and "Malicious", According to His 'Hired Guns' in London
- it was framed as "malicious"
- Links 27/04/2026: Strikes, Corruption in Spain (Spanish PM Sanchez' Wife), and YouTuber Faces Jail Time
- Links for the day
- Gemini Links 27/04/2026: Gopher Catch-up, Year of Contentment, and Path to Freedom
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, April 26, 2026
- IRC logs for Sunday, April 26, 2026
- Journalistic Malpractice: Helping Microsoft Paint 'Voluntary' Layoffs (Before PIPs) as "Buyouts"
- What does this tell us about today's media?
- The Man IBMers Regard or Already See as Likely Successor of Krishna (or Next CEO of IBM) is a Slop Fanatic
- How dangerously misguided
- The Corrupt Lecture the Non-Corrupt - Part VI - Management of the European Patent Office (EPO) Covered Up Cocaine Use, Even Colleagues Not Informed
- the self-described "fu--ing president"
- Who Controls Fedora? IBM and GAFAM.
- Don't for a moment believe that IBM understands GNU/Linux. We are quite certain nobody in IBM's Board of Directors uses it.
- State of Slop About GNU/Linux
- As the incentive to publish is reduced (competing with slop is no fun), the effort/money invested in stories goes down
- Links 26/04/2026: Korean Inflation, GLP-1 Drugs Linked to Cognitive Impairment, Lithuania's Public Broadcaster LRT Besieged
- Links for the day
- Hopefully Smooth Sailing in OS Upgrade
- There are some contingencies at hand
- Links 25/04/2026: "Horrible Economics of AI Are Starting to Come Crashing Down", More Restrictions Placed on Social Control Media
- Links for the day
- Getting Aggressive Suggestive of Loss - Part IV - Shutting Down My Existence
- Would anyone out there tolerate such messages sent from burner accounts?
- Gemini Links 26/04/2026: Gemini Movie Database (or GeminiMDB) and Star Trek III
- Links for the day
- Weeks Before Linux Removed Over 100,000 Lines of Code Due to Slop 'Bug Reports' Microsoft Paid 'Linux' Foundation to Advance Slop in the Name of 'Security'
- What can possible go wrong? Both for security and for stability.
- Tracking Ages of People
- To stay "safe" tell us your age
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, April 25, 2026
- IRC logs for Saturday, April 25, 2026
- "A single witness shall not rise up against a person regarding any wrongdoing or any sin that he commits; on the testimony of two or three witnesses a matter shall be confirmed." (Deuteronomy 19-21)
- The spouse of Garrett repeatedly points out that Garrett can barely code or can only do so very poorly
- Rust People Sabotage Stability for the Sake of a Falsely-Promised 'Security'
- Set aside severe performance issues, poor handling of "edge cases", general bugs, lack of compatibility, and even crashes
- SLAPP Censorship - Part 57 Out of 200: 5RB and Brett Wilson LLP Made the Garrett and Graveley Particulars of Claims a Lot Like Photocopies!
- They seem very much irritated that I speak about this
- Huge Strike at the European Patent Office (EPO) This Coming Friday (May 1st)
- International Worker’s day
- Links 25/04/2026: Nokia Wins Embargo in Kangaroo Court Where Judges Are Salaried Nokia Staff (UPC), Allison Pearson Defamation Case (UK) Succeeds, Smokey Robinson and "Puff Daddy" (US) Fail
- Links for the day
- Gemini Links 25/04/2026: Weekly Echoes, Gemtext Tables, and Using Offpunk
- Links for the day
- Corporate Media Did Not Specify What Microsoft Means by "Buyouts" (Layoffs), It May Be Hardly Different From Severance
- Time will tell, but investigative journalism hardly exists anymore, so we won't hold our breath
- The Corrupt Lecture the Non-Corrupt - Part V - "Diversity" and "Inclusion" at EPO Means Sleeping With Sister of "Cocaine Communication Manager" and Making Them Millionaires
- Remember that top applicants or key stakeholders of the EPO are already complaining about a lack of quality
- Links 25/04/2026: Fake GAFAM Valuations (Gripping the Market Based on False Accounting), "Evidence Isn't Just for Research", and "Putin Defends Mobile Internet Outages"
- Links for the day
- Dr. Andy Farnell on Why Calling Slop or Chaff "Hey Hi" (AI) Harm Us All, Except for "Ten or Twenty Rich Industrialists"
- "words to avoid"
- Internet Trolls Likely Trying to Distract From the Demise of IBM, Problems With Red Hat
- there seems to be trolling online aimed at suppressing discussion
- Debian Upgrade Coming Up (Soon)
- Yesterday we contacted the datacentre staff about it
- Getting Aggressive Suggestive of Loss - Part III - Threats From Burner Accounts Formally Treated as a Crime
- Countries that cannot preserve freedom from self-censorship are countries where free press ultimately cannot prevail
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, April 24, 2026
- IRC logs for Friday, April 24, 2026
- Gemini Links 25/04/2026: 3.4k+ Capsules, Microsoft Layoffs, Call for Nuclear Disarmament, "Internet is Sad and Lonely"
- Links for the day