New vulnerability in Vista won’t be patched until SP2

Analysis
Nov 20, 20081 min

The most worrisome hole is the kind that doesn’t need a user to be logged in with administrative rights. A researcher says he found such a hole in Windows Vista that could allow an attacker to load a PC up with unauthorized

code.

The hole depends on the device I/O control, which handles internal device communication. Researchers at Phion have found two different ways to cause a buffer overflow that could corrupt the memory of the operating system’s kernel. Phion reportedly notified Microsoft about the problem on Oct. 22 and word is that Microsoft will have a patch ready for Vista’s next service pack, scheduled for release in June 2009.

Visit the Microsoft Subnet web site for more news, blogs, podcasts. Also see:

Advocate says IPv6 will reduce global energy usage10 questions for Small Business Server/Essential Business Server guy, Russ Madlener7 Keys to cleaning up Windows with Windows 717 job-hunting resources for Windows prosGlenn Weadock on Windows Server 2008Library of Windows management tools from A Better Windows Worldall Microsoft Subnet bloggers.bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)

Subscribe to

Sign up for the