Page 1 of 2 12 LastLast
Results 1 to 10 of 18
  1. #1
    Righteous Dude
    Overall activity: 47.0%

    Join Date
    Aug 2009
    Location
    Bay Area, California
    Posts
    1,899
    Liked
    783 times
    Points
    25,850

    New Windows Vulnerability Uncovered

    The last days have not been pleasant for Microsoft. A new Windows vulnerability affecting all 32-bit editions of the operating system from Windows 3.11 to Windows 7 was uncovered shortly after the revelation that an exploit in Microsoft’s Internet Explorer 6 was used in the attack on several US companies that included Google and Adobe (read Microsoft Confirms Internet Explorer Vulnerability)

    Cause of the problem is the virtual dos machine (vdm) that was introduced in 1993 to support 16-bit applications. The exploit was uncovered by Tavis Ormandy, a member of Google’s security team. It makes it possible to run code with elevated rights on the computer system. The full technical explanation of the vulnerability and example exploit code are available at Neohapsis.

    No patch has been issued by Microsoft until now even though Ormandy mentioned that he had contacted Microsoft about the issue six months ago. There is however a quick fix for most Windows operating systems: Disallowing VDM.

    There are two possibilities on how to do that. System administrators and users with access to the Windows Group Policy Editor and an operating system that is Windows 2003 or newer can enable the policy to “Prevent access to 16-bit applications” in Computer Configuration > Administrative Templates > Windows Components > Application Compatibility”.



    This setting has the consequence that 16-bit applications will not execute on the computer system which should not have an effect on most home users.

    Users with operating systems prior to Windows 2003, Windows XP comes to mind, can alternatively create a new Windows Registry key to close the security vulnerability in the operating system.

    This is done by navigating to the Registry key

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat

    and creating the new DWORD VDMDisallowed and setting the value of the Dword to 1.


    http://www.ghacks.net/2010/01/20/new-windows-vulnerability-uncovered-security/

    A Guy

  2. #2
    Newbie
    Overall activity: 0%

    Join Date
    Nov 2009
    Posts
    83
    Liked
    0 times
    Points
    2,102
    17 years? OMG, i'm lost for words lol

  3. #3
    Newbie
    Overall activity: 0%

    Join Date
    Dec 2009
    Location
    Ontario Canada
    Posts
    32
    Liked
    0 times
    Points
    1,755
    Thanks for the info A Guy.

  4. #4
    Verified Member
    Overall activity: 0%

    Join Date
    Dec 2009
    Posts
    300
    Liked
    0 times
    Points
    3,229
    Thanks for the info A Guy.. Will disable that right now..

  5. #5
    Modern-day Romeo
    Overall activity: 18.0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,159
    Liked
    476 times
    Points
    60,895
    Somehow I'm not bothered about this....seems like a trivial matter to me
    They call me the mysterious one...
    my motto is...when it's hot, chill baby

  6. #6
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    318 times
    Points
    26,077
    We had a 20+ year bug in Unix\Linux that was fixed recently.
    pacman -Syyu life not found in sync db

  7. #7
    Newbie
    Overall activity: 0%

    Join Date
    Nov 2009
    Posts
    83
    Liked
    0 times
    Points
    2,102
    20 year bug in Linux?

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2009
    Posts
    2,046
    Liked
    0 times
    Points
    28,383
    well thx for info but i dont have this AppCompat key
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat
    now what
    Last edited by noaccount; 01-22-2010 at 07:04 AM.

  9. #9
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    318 times
    Points
    26,077
    Quote Originally Posted by *Danielx386 View Post
    20 year bug in Linux?
    Yeah... we couldn't think of a work around until recently.

  10. #10
    Experienced User
    Overall activity: 0%

    Join Date
    Nov 2009
    Location
    A live-able place.
    Posts
    386
    Liked
    53 times
    Points
    12,670
    DAMN! just one registry key?!? OMG that shatters the hell out of Windows 2003 and Windows XP. This'll make me more aware of my computer

    good to know about this. Thanks for sharing!
    Here to prevail on your failures.

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Replies: 4
    Last Post: 11-04-2011, 11:46 PM
  2. Replies: 17
    Last Post: 09-16-2010, 05:39 AM
  3. Replies: 10
    Last Post: 07-22-2010, 01:57 AM
  4. IE Windows vulnerability coughs up local files
    By A Guy in forum Spyware/Viruses
    Replies: 0
    Last Post: 01-29-2010, 01:11 PM
  5. windows vulnerability scan
    By dazofdarlo in forum General Forum
    Replies: 0
    Last Post: 08-05-2007, 01:49 AM
All times are GMT +8. The time now is 03:51 AM.