SkyRecon IDs New Microsoft Vista Vulnerability

SkyRecon research team provides information leading to patch of Vista flaw

Dark Reading Staff, Dark Reading

December 14, 2007

1 Min Read
Dark Reading logo in a gray background | Dark Reading

SAN JOSE, Calif. -- SkyRecon Systems, the premier provider of unified endpoint security solutions, today announced that its research team uncovered an elevation of privilege vulnerability CVE-2007-5350 in the Microsoft® Windows® Vista™ operating system.

"Windows Vista includes many new enhancements and features which improve the overall operating system security," said Thomas Garnier, Senior Research Engineer at SkyRecon Systems, Inc. "During our ongoing research in the Windows Vista kernel and the ALPC interface, we found an important vulnerability which could be used to gain privilege and then execute code in the Vista kernel."

Affecting the kernel in both the 32-bit and 64-bit versions of Windows Vista, the identified vulnerability could allow an attacker to take complete control of the affected system. The attacker could use their increased privileges to install programs; view, modify, erase, or remove data; or even create new accounts that possess full administrative rights to the system, applications, and data.

More information regarding the vulnerability and Microsoft Security Bulletin can be found at:

Microsoft Security Bulletin MS07-066 - Important Vulnerability

"Vulnerability research is a critical component in designing generic, effective, and efficient layers of protection," said Yann Torrent, Director of Research and Development at SkyRecon Systems, Inc. "At SkyRecon Systems, our research team aims to understand each Windows component in order to identify possible threats such that comprehensive protections can be built within our unified endpoint protection solution."

SkyRecon Systems

Read more about:

2007

About the Author

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights