EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

12.29.08

Windows Vista Left Vulnerable Over Christmas

Posted in Microsoft, Samsung, Security, Vista, Windows at 7:49 pm by Dr. Roy Schestowitz

Broken glass

AS WE POINTED OUT on Christmas day, Microsoft left its users/clients vulnerable over the holidays. But there’s actually more than we mentioned at the time. One of our readers points out that new flaws were found — accompanied by exploits — that can hijack Windows Vista and predecessors (Vista was never secure anyway).

The following exploit utilizes the XML vulnerability in Internet Explorer to execute arbitrary code under Vista.

Here is another new one:

A vulnerability was reported in Windows Media Player. A remote user can cause arbitrary code to be executed on the target user’s system.

Over at The Register, it is being reported that Samsung picture frames are dangerous to Windows users (“The disc is needed to use the kit as a USB monitor on windows XP machines”). We’ve covered the follies of Samsung in the past because they stabbed Linux in the back by signing a patent deal with Microsoft.

The BBC labels 2008 an unprecedentedly bad year for security, but surely it won’t get any better in 2009, not when about 40% of all (Windows) machines are zombies and many people are out of work.

Criminal gangs generate so many viruses for two main reasons. Firstly, many variants of essentially the same malicious program can cause problems for anti-virus software which can only reliably defend against threats it is aware of.

Bearing in mind everything that people already know and witness, the BBC does write: “The vast majority of these malicious programs are aimed at Windows PCs. Viruses made their debut more than 20 years ago but the vast majority of that million plus total have been created in the last two-three years.” It later shows the Windows logo above a caption that says “Most attacks are aimed at PCs running the Windows operating system.”

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

3 Comments

  1. Thomas Holbrook II said,

    December 30, 2008 at 5:18 am

    Gravatar

    This doesn’t surprise me in the least. It reminds me of the whole metafile fiasco in which users of Windows were left out in the cold for an entire year. Then Steve Gibson digs a bit deeper and discovers that it was not a bug, but yes… an actual feature. It was one of those things that probably sounded like a good idea at the time (though I personally can’t figure out for the life of me why pictures should be executing binary code in the first place), then was neglected for quite some time.

  2. aeshna23 said,

    December 30, 2008 at 9:01 am

    Gravatar

    I noticed that the vulnerabilities involved using Microsoft products on Vista. Now, I’m sure if one must use Vista or XP, you should Firefox and not IE for security. Should one also use foobar2000 or dbpowerAmp instead of Windows Media Player? I have my suspicions that MS own programs tend to be security risks on Windows platforms than do third party applications–not simply because the hackers hack them more, but by corporate policy of giving these programs greater privileges than ordinary (and sensible) programmers would. Does anyone know if this is the case?

  3. Roy Schestowitz said,

    December 30, 2008 at 9:31 am

    Gravatar

    “I have decided that we should not publish these extensions. We should wait until we have a way to do a high level of integration that will be harder for the likes of Notes, Wordperfect to achieve, and which will give Office a real advantage.”

    Bill Gates [PDF]

    Enough said.

    Think about ActiveX too. It’s about binding the Web browser and Web sites to one operating system.

    “Another suggestion In this mail was that we can’t make our own unilateral extensions to HTML I was going to say this was wrong and correct this also.”

    Bill Gates [PDF]

What Else is New


  1. Links 1/8/2015: Steam Sale, blackPanther OS 14.1

    Links for the day



  2. Vista 10 Inherently Criminal: Vandalising the Competition (Dual Boot, Rival Web Browsers, Online Services)

    Vista 10, the latest incarnation of Windows, takes its anticompetitive aspects to a whole new level, betraying even so-called 'partners' in the process



  3. As Microsoft AstroTurfing/PR Budget Runs Dry, Vista 10 Truths Come Out

    The media manipulation by Microsoft (to the tune of hundreds of millions of dollars spent on 'marketing') grows thin as a growing number of growingly angry early adopters of Vista 10 publicly rant



  4. Links 31/7/2015: Lennart Poettering as 'Linux Hero' and systemd Conference Coming

    Links for the day



  5. Links 30/7/2015: Apache Spark on Z System, Elive 2.6.8 Beta

    Links for the day



  6. Microsoft's Mouthpiece Mary Branscombe Tries to Shoot Down Free Software, But Fails Miserably

    At the CBS-owned ZDNet, which is Free/Open Source software-hostile, new FUD surfaces, but the FUD is so flawed that a full rebuttal is easy and almost imperative



  7. People of New Zealand Must Rise Up to Defend Sovereignty and Stop Software Patents

    The TPPA serves to override (launder) the law of New Zealand, allegedly legalising patents on software in the process



  8. Microsoft Illegally Evades Billions of Dollars in Tax, Says IRS

    The criminal enterprise known as Microsoft finds itself embarrassingly exposed in the courtroom, for the IRS belatedly (decades too late) targets the company in an effort to tackle massive tax evasions



  9. Vista 10 Very Buggy Upon Release, Just as We Have Repeatedly Warned for Weeks

    Vista 10 is prematurely pushed out the door (to meet a deadline) way ahead of it being stable, even remotely polished, and supported by hardware companies (there is a serious drivers issue)



  10. Surveillance Machine With a Keylogger: Vista 10 Will Spy on the User (Over the Internet) Even While Playing Games

    Microsoft is making it clear that even playing a simple game like Solitaire on Vista 10 will make one subjected to spying (for targeted ads); other serious violations of privacy revealed upon release



  11. Links 29/7/2015: Akademy 2015 Ends, NetBSD 7.0 RC

    Links for the day



  12. MPEG-LA is Preparing New Patent Obstruction (Called DASH) Against Free Software, OIN Grows

    A new conspiracy against free multimedia software, set up by the MPEG cartel, is called DASH



  13. New Zealand's Media Gets History Wrong on Software Patents

    Setting the record straight on the fight against software patents in New Zealand



  14. Not Only Vista 10 Crashes a Lot, Any .NET Application Does Too (Updated)

    Microsoft software is quickly becoming synonymous with crashes as any piece of software developed with Microsoft's tools, not just the underlying platform, crashes chronically



  15. The Government of Bulgaria Sells Out to Microsoft, Again

    Despite some promises and reassurances that Bulgaria will consider Free/libre software, the Bulgarian government hands out a lot more of taxpayers' money to the Mafia



  16. Corporate Media Finally Finds Out That Vista 10 Crashes a Lot

    Stability issues of Vista 10 are belatedly reported to be a major catastrophe, leaving it unusable for many early adopters



  17. Links 28/7/2015: Linux 4.2 RC4, New Logos and Bug 'Branding' for FUD

    Links for the day



  18. Patents Roundup: Technicolor, Alice, Voip-Pal, Fitbit, Marijuana Patents, and JDate

    A look at some of last week's patent news, with imperative responses that criticise corporate exploitation of patents for protectionism (excluding and/or driving away the competition using legal threats)



  19. Corporate Lobbyists Including Koch-Connected Front Groups Attack Real and Perceived Patent Reform in the United States

    Looking at some of the latest propaganda for and against a bill which is already too watered-down to actually fix the US patent system



  20. Patents in the Android World Further Complicate Freedom in This Linux-Powered Platform

    A survey of last week's news with special focus on Google and Android, which are trying to coexist and thrive in a world full of patent maximalists



  21. The 'Unitary' Patent Trojan Horse Rammed Down the Throat of Europe

    Under the guise of 'unification' or 'unity', existing patent systems are being abandoned and more power gets passed to corrupt EPO officials



  22. HEVC Cartel is Not News, Only the Names of Backers and the Costs Are New

    A few remarks on and a roundup of recent articles about HEVC, which we first wrote about in spring



  23. IRC Proceedings: July 12th, 2015 – July 25th, 2015

    Many IRC logs



  24. Links 26/7/2015: Purism Librem and Freedom, Akademy Updates

    Links for the day



  25. Vista 10 (Windows 10) Has NSA Back Doors and Front Doors

    Vista 10 to bring new ways for spies (and other crackers) to remotely access people's computers and remotely modify the binary files on them (via Windows Update, which for most people cannot be disabled)



  26. Vista 10 Not Ready, But Released Anyway

    Despite severe technical issues in the rushed-out-the-door Vista 10, Microsoft decides to stick with the deadline, only days after reporting billions of dollars in losses



  27. Links 25/7/2015: Plasma Mobile, Linux Mint 17.2 OEM

    Links for the day



  28. Links 24/7/2015: openSUSE Leap 42.1, Intel With Rackspace for OpenStack

    Links for the day



  29. Links 24/7/2015: GNOME 3.17.4, Mozilla Developer Network Turns 10

    Links for the day



  30. Microsoft Has Run Out of Attempts and Vista 10 Will Definitely Fail

    As Microsoft admits billions of dollars in losses just days before Vista 10 is pushed as a 'free' upgrade, there is no concrete sign that financial recovery is imminent, for the bigger cash cow (Office) suffers a similar fate


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts