Microsoft admits it messed up Windows 7 security

Market

Following a week where no less than two security flaws were reported in Windows 7 which were officially dismissed and not constituting a vulnerability, it seems there has now been a rather huge change of mind at Microsoft and a frankly astonishing confession.

Microsoft has been at the sharp end of the flawed security stick this week, and the funny thing is it seems that they both made the stick and have been responsible for the continued prodding with it.

In an attempt to make all six versions of Windows 7 less irritating than Vista, Microsoft decided to change the default action of the User Account Control (UAC) feature so that it no longer pops up for permission every time changes are being made to the OS.

People have been asking questions of Windows 7 security for some time, so it should come as no surprise that it did not take long for the security research community to twig that this could be a little on the silly side when talking about system security.

The problem being that by allowing certain digitally signed third party executables to bypass UAC by default, Windows 7 becomes exposed to the potential of piggybacked third party code.

Malware can exploit elevated instances of rundll32.exe to point to malicious payloads which inherit the UAC OK from the parent process.

One researcher, Long Zheng, writes about how he developed a fully functional proof-of-concept app in VBScript to easily disable UAC entirely.

So that is two UAC related Windows 7 security flaws in a single week. You might think that Microsoft would take them seriously, very seriously indeed.

Yet the initial response was one of total denial: "Microsoft’s position that the reports about UAC do not constitute a vulnerability is because the reports have not shown a way for malware to get onto the machine in the first place without express consent" said spokesman Jon DeVaan.

More detail about the Windows 7 security flaws and more on that Microsoft U-turn follows on page 2...

STORY CONTINUES



SPONSORED PRESS RELEASES

Independent Research Shows High Customer Satisfaction for NetSuite
NetSuite Inc. (NYSE: N), a leading vendor of cloud computing business management software suites, today announced that technology advisory firm Nucleus Research has completed an independent survey of NetSuite customers and concluded that NetSuite customers are highly satisfied, l...

Featured IT jobs

Senior Software consultant responsible for providing support on a unique enterprise level software solution for various customers, Melbourne based!
Skills Tags:   IT  ITIL  Linux  Management  RFP  Unix
This financial client has an excellent opportunity for an experienced Database Developer. SQL 2005 Some Schema design + SSIS & SSRS - 80k+super
Skills Tags:   Design  Development  SQL  SQL Server
Massive Hyperion Project requires a Hyperion Planning Architect / Lead Developer - drive home a huge Hyperion solution.
Skills Tags:   Architect  Design  Development  Hyperion
OBIEE Consultant to work on a very large greenfield OBIEE implementation to date to work end-to-end with excellent modelling & BI Server skills
Skills Tags:   Business Intelligence  Cognos  Hyperion  Informatica  Oracle  SQL

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases