By Jennifer LeClaire TechNewsWorld
12/27/06 12:02 PM PT
Microsoft's claim of superior security in its new Vista Vista OS already faces challenges, with a set of vulnerabilities reported Tuesday that affect IE and Firefox Web browsers, as well as the Exchange Server. Though a hacker could exploit these flaws to commandeer a Vista-based computer, the software giant insists the problems are minor.
For all the talk about safety and
security as a foundational promise of Windows Vista, Microsoft's (Nasdaq: MSFT) new operating system, released to business users in late November, has already been found to contain several potentially serious vulnerabilities.
A programming flaw, thought to be the first identified in the new OS, could let hackers take full control of a computer running the software. It was recently disclosed on a Russian Web site.
Another flaw, which can be executed via Internet Explorer and Firefox Web browsers, can corrupt memory during handling of certain types of requests.
Yet another flaw has been identified in Microsoft Exchange. It allows anyone to shut down the Exchange server by sending a malformed e-mail . Though this flaw does not allow a remote attacker to take over the system, it does cause the mail server to crash.
Microsoft's Spin
Microsoft has seen its share of security flaws in its earlier operating systems, browsers and other products; however, the Vista flaw is a black eye on a new product that Microsoft spent years developing and has touted for its robust security features.
Microsoft said it is investigating the threat and so far has found that a hacker must already have access to a vulnerable computer in order to launch an attack.
"Currently, we have not observed any public exploitation or attack activity regarding this issue. While I know this is a vulnerability that impacts Windows Vista, I still have every confidence that Windows Vista is our most secure platform to date," said Mike Reavey, operations manager of the Microsoft security response center.
The Real Story
The relative impact on Vista users is small, according to most security researchers. The breaches don't seem to be critical, and the software is not widely deployed. Most corporations that are running Vista are in trial mode, and consumers won't have a chance to upgrade or buy new computers with Vista until January 30.
That means Microsoft still has time to make corrections before the product hits store shelves. Vista and other current-generation software offer the ability to self-update and apply any security patches during the installation process. The time to find issues with the program, however, is growing short.
News of a Vista flaw could hinder public perception, according to Enderle Group Principal Analyst Rob Enderle, and that's good news for antivirus software companies.
"It doesn't really matter if Vista is invulnerable or not. No product is invulnerable. If the buying public views the product as good enough -- much like Apple (Nasdaq: AAPL) users don't feel they need antivirus products -- then they won't buy antivirus products for Vista," Enderle told TechNewsWorld.
Security Firms' Stake
Security software firms, including
McAfee and
Symantec (Nasdaq: SYMC), do not want to see that happen.
"No company, from McAfee all the way to Kaspersky, can maintain revenue if folks who deploy Vista stop buying their products. Security firms are having a major coronary over that possibility," Enderle claimed. "The firms have been working pretty hard to try to find holes and create a viable threat."
Opera Takes On Phishers With Latest Browser Release December 20, 2006
As an increasing number of Internet users shop online, phishers -- thieves who dupe users into performing transactions or sharing information with phony but legitimate-looking Web sites -- are taking advantage of the higher volume of potential targets, according to Opera CEO Jon von Tetzchner. "Cybercriminals are very active during the holiday season," he said.
Related Stories
Vista and the Future of OS Security, Part 1 December 19, 2006
Microsoft has a lot riding on its new security features in Vista, according to Ed Moyle, a security services manager at CTG. However, he does not think that tighter security will necessarily make Vista a less appealing target for attackers. Instead, he expects Vista to be the top target for attackers going forward.
Vista Hits, Sony Kills Blu-ray, the Birth of Megatasking December 04, 2006
When the security industry itself is saying it needs massive help, the only thing that can be done is to change how the game is played. While there are a number of compelling benefits to Vista, the big one is that it gives the security industry a chance to get ahead of the wave.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.