[ news_security_news ] Important Windows Flaw Discovered
Chris Crum Staff Writer
2005-12-13
Insider Reports RSS Feed
eEye Digital Security has discovered an important vulnerability related to Microsoft Windows.
It is being called the Windows Kernel Elevation of Privilege Vulnerability and it allows any code executing on Windows 2000 SP4 and Windows NT 4.0 machines to elevate itself to the highest possible local privilege level.
eEye says that by doing so, the vulnerability could potentially be used in conjunction with a virus, worm or trojan to allow unprivileged code to subvert the operating system and provide the attacker with SYSTEM-level privileges, which would convert the vulnerability from important to critical.
"A kernel-level vulnerability is by nature, harder to fix, so we understand the time it took Microsoft to issue a patch," said Marc Maiffret, eEye's co-founder and chief hacking officer.
"This vulnerability is unusual in that it represents a growing trend of blended threats attackers are using to subvert systems remotely," added Maiffret. "These types of threats highlight the need for enterprises to focus on host-based solutions that enable them to make their networks zero-day immune."
For more details about this vulnerability, check out eEye's press release on the topic here.
About the Author:
Chris Crum is a staff writer for SecurityProNews and WebProNews.
More news_security_news Articles
Insider Reports RSS Feed
|
|