Comments on: Windows Mail bug may expose Vista users
Possible security vulnerability in Windows Mail could be exploited by attackers to run programs on Vista PCs.
Possible security vulnerability in Windows Mail could be exploited by attackers to run programs on Vista PCs.
January 2, 2010 4:16 PM PST
January 2, 2010 3:30 PM PST
January 2, 2010 11:43 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
IF the users haven't turned off Vista Program Protection. The little popups that everyone complains about. If the program that is ran can do any damage, they should receive a popup asking if they really want to run / do that action.
Coupled with this little tidbit:
[i]"Painting to the screen is another action that is not blocked by UIPI. The USER/graphics device interface (GDI) model does not allow control over painting surfaces; therefore, it is possible for a lower privilege application to paint over the surface region of a higher privilege application window."[/i] *
...and one could theoretically paint an invisible window over the desktop that reads the information below that window, remains on top the whole time, and simply copies all data passing through it.
...et voila', UAC becomes pretty much useless at that point.
* ref'd from: http://msdn2.microsoft.com/en-us/library/aa480150.aspx
/P
Why is it anyone would use Microsoft e-mail or Office products, when other products do not have these problems?
Now here we have yet another Microsoft e-mail virus opportunity. When will it end? Never. At least not while Microsoft continues to make e-mail products.
"Depending on what the malicious link tells Windows Mail to do, the threat to Vista users could be significant, said Dave Marcus, security research and communications manager at software maker McAfee. "Theoretically, attackers can do a lot of things; they will be able to pass any command through it," Marcus said."
Let me re-write that for you Dave.... "Depending upon how much C4 was installed in your PC at the factory...or how much McAfee software you have loaded...your PC could either blow up or blue screen. Theoretically.....or more like realistically the success of products from MS like OneCare that are cheaper and less envasive to the users PC.....we will be out of buisness and so I must make up cr@p to scare people off.
Hahahahahahahhahahhahhah
/P
Of course this hole is a danger.
It does not mean your new Vista box is "bad," it just means there
are real risks.
Why the negativity? The hate?
However, its market-place weaknesses are...
Wait...
Whats the posting, character-count, limit again..?
SHEESH, our companys been testing "Vista" for many months now, and weve yet to see a single element of "Vista" (functionality, performance, consumer-rights, market-demand, pricing, third-party development, OR security) which isnt a disaster.
Thank goodness, we havent had ANY customers, what-so-ever, who actually want it.
I can't think of anything else to say except 'I told you so'
http://www.apple.com/hardware/
http://www.dell.com/content/products/productdetails.aspx/precn_390?c=us&l=en&s=bsd&cs=04
As such, the "may expose" needs to be re-written as "exposes". Stop using passive tense and write in active tense!!!
Similar with "A possible security vulnerability" needs to be re-written in active voice as "a security vulnerability".
On a simlar note, "could let attackers" needs to be re-written as "lets attackers".
Is this "be kind to Microsoft week" or what? Report it AS IT IS... NOT AS MICROSOFT WISHES IT TO BE!!!
Walt
It might have been demonstrated, for example, that ther exists a buffer overrun, but not that it is exploitable. To be exploitable it would need to meet some other requirements such as predictability of the context in which it is run, which is not always the case.
The reporter used accurate language. Reporting it as you suggest would be showing bias. Which, obviously, you have.
- Vista does suck
- by rmiecznik March 26, 2007 8:23 AM PDT
- It wouldn't even install on my machine, and I have a new computer
- Like this Reply to this comment
-
(22 Comments)too, 1 year old, I get a hardware blue screen, something it chokes
on. XP runs great, this will be my last MS OS.
I already switched to Mac OS and Linux 2 years ago.