Microsoft finds vulnerabilities in Vista, W7 gadgets

 

Security risk for admins.

Microsoft has urged Windows Vista and Windows 7 users to disable desktop accessories in the operating systems as a security measure.

The software giant said in a security advisory that the insecure Gadgets feature in the systems can execute arbitrary code as well as access user data.

Users logged on as administrator, guest or power user could unwittingly allow rogue Gadgets to run any code it wants at that security level, and take complete control over the system, according to Microsoft.

The advisory includes an automated  "Fix It" tool disabling the features.

While Microsoft did not outline the specific vulnerabilities, a briefing at the Black Hat security conference later this month promises to provide greater detail on the issue.

Gadgets — developed with JavaScript, CSS and HTML — are embedded into the Windows operating system by default, potentially providing a number of interesting attack vectors, according to researchers Mickey Shkatov and Toby Kohlenberg.

All editions of Windows Vista Serivce Pack 2 are affected by the vulnerability, as well as the entire Windows 7 operating system family.

Copyright © iTnews.com.au . All rights reserved.


Microsoft finds vulnerabilities in Vista, W7 gadgets
 
 
 
 
Top Stories
Photos: Google I/O 2013
Evolution not revolution.
 
Photos: NextDC builds S1 data centre
Prepares for September launch.
 
QLD Govt contributed to payroll project 'death spiral'
Inquiry hears from independent expert.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest articles on BIT Latest Articles from BIT
eftpos to trial "mobile wallet"
May 17, 2013
eftpos, the operator of Australia's most widely used debit card system will soon start a mobile ...
New iiNet 4G phone plans include free calls between phones on same account
May 16, 2013
iiNet's new 4G mobile business plans provide free calls between handsets on the same account as ...
Revealed: $1,000+ for Microsoft's Surface Pro in Australia, with keyboard
May 16, 2013
You'll pay more than $1,000 for Microsoft Surface Pro with a keyboard, Microsoft has officially ...
Is this the future of business laptops?
May 15, 2013
The Lenovo ThinkPad Helix is a fully-fledged business laptop running Windows 8 Pro, but detach ...
Federal Budget 2013: So what are you going to be required to pay?
May 15, 2013
Opinion: Want a handy summary of the 2013 federal budget? Here is one by Newcastle accountants ...
Latest Comments
Polls
Do you prefer the Coalition's NBN policy?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 1610

Vote