Results 1 to 3 of 3

Thread: Vulnerability in the TCP / IP stack in Vista?

  1. #1
    Join Date
    Oct 2008
    Posts
    213

    Vulnerability in the TCP / IP stack in Vista?

    Unterleitner Thomas, an employee of the publisher phion Austrian security, said he discovered a vulnerability in the TCP / IP Windows Vista operating system that could allow the execution of type attacks buffer overflow or overrun buffer. He explains that he informed Microsoft of the existence of this vulnerability in late October, and affirms that the publisher did not intend to make the necessary corrections before the release of Service Pack 2, or SP2, Windows Vista, that 'expectations for the first half of 2009.


    According to security bulletin published on November 20 by phion, the existence of this vulnerability has been found in 32 editions and 64-bit Windows Vista Enterprise and Ultimate, and SP1 would not change the situation. According Unterleitner, some queries using the library Iphlpapi.dll could cause a buffer in the memory used by the kernel, and cause the system crash, resulting in the appearance of the famous BSOD (Blue Screen of the Death). Eventually, it can be assumed that this buffer overflow allows the injection of code in system memory, and therefore encourages the remote control of the machine.

    To exploit this flaw, however, it is that the attacker has - or ownership - the rights administrators on the machine on the network, puts the researcher, however, that evokes the possibility of bypassing this protection through a package DHCP specially designed. In the end, despite the existence of a vulnerability, the risks are fairly low, which probably explains why Microsoft has not - at least for now - include the vulnerability in its program of updates December.

  2. #2
    Join Date
    Oct 2008
    Posts
    210

    Re: Vulnerability in the TCP / IP stack in Vista?

    The fact that the flaw is important enough does not mean Microsoft. Linux such flaw is corrected 24-72H max ...

  3. #3
    Join Date
    Mar 2008
    Posts
    212

    Re: Vulnerability in the TCP / IP stack in Vista?

    The good thing is that it shows that UAC is good for something. As against, wait for the SP2 to correct the flaw as minor as it is, it really cares.

Similar Threads

  1. Microsoft Bluetooth Stack for Vista [ MS USB BTH]
    By Luma in forum Vista Hardware Devices
    Replies: 3
    Last Post: 24-09-2009, 03:26 AM
  2. Windows Vista Bluetooth Stack & Drivers
    By mikey32 in forum Operating Systems
    Replies: 3
    Last Post: 06-06-2009, 11:38 AM
  3. Vulnerability in Mac OS X
    By timon in forum Operating Systems
    Replies: 3
    Last Post: 26-02-2009, 10:20 AM
  4. Bluetooth Stack (Toshiba) incompatible with Vista
    By marstacy in forum Vista Help
    Replies: 4
    Last Post: 04-01-2008, 10:09 PM
  5. Bluetooth, Changing from Toshiba stack to MS stack
    By LaKisha in forum Vista Hardware Devices
    Replies: 1
    Last Post: 18-10-2007, 11:25 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,548,142.84748 seconds with 16 queries