Affected 32- bit operating system
Microsoft has been reeling out a variety of operating systems. They started with a partial GUI and later continued in developing a complete GUI. The Windows version can be broadly categorized in DOS based and NT based. All the currently available operating systems are of the NT category. However, all the available operating systems have in fact carried forward a vulnerability that may have a risk of its own. The vulnerability that has survived is the one observed in BIOS calls to the Virtual 8086, which is actually a mode monitor code. This code was introduced back in the 1993-94 in the Windows NT 3.1 and has been carried forward upto Windows 7. This repetition of code has given a scope of vulnerability in every release and is almost 17 years old.
Hence, Microsoft has acted on this, and has released a Security Advisory 979682 to help customers minimize the vulnerability until a repair patch has been available. The vulnerability that has been observed is the EoP or the Elevation of Privilege Vulnerability. This was first indicated by Google Engineer Tavis Ormandy. This vulnerability was first sought in the Windows NT # GP Trap Handler security codes. This weakness in the code can actually allow a hacker to hack in any system from a non-administrator to an administrator level and take charge of all the administrative privileges. Unfortunately, this bad patch is only to affect the 32-bit version of operating system namely the Xp and Vista. The 64-bit machines are left unaffected.
The security advisory contains guidance for the PC users to protect their systems against the exploitation of this vulnerability. However, there have been no attacks of hackers on a wider base; Microsoft believes that it is certainly a risk to its customers. The Senior Security program manager of Microsoft, Jerry Bryant has urged the customers to at least go through the advisory and implement the suggested precautionary measures.
Popularity: 1% [?]
Share and Enjoy:
|
|






















