Feeds

Creaky old Windows flaw rises, divides doommongers

It's either no biggie, or hot buttered death

Securing Web Applications Made Simple and Scalable

A new Windows-based denial of service attacks reportedly exploits a 10-year old OS flaw to crash vulnerable systems.

Independent security experts downplay the likely impact of the bug even though 2X Software, the virtual computing firm that discovered the bug, is talking up its supposed seriousness. Versions of Windows from the latest Windows 7/Server 2008 versions down to Windows 2000/Server 2003 are affected by the flaw, according to 2X.

2X, which is not well known in the world of information security research, issued a press release over its discovery on Wednesday billing it "one of the biggest security vulnerabilities in the Windows OS for many years".

Beyond saying the bug can result in a blue screen and system reboot, 2X's release is scant on details. Independent security experts are suspicious of reading too much into 2X's claims.

"Given the immediate explanation it doesn't seem likely that we would even consider it a vulnerability - and if we do, then it only seems to be a local denial-of-service," said Thomas Kristensen, CSO of security notification firm Secunia. "This means that the most 'critical' scenario is where users [have] already got legal access to a terminal server or other multi user system which they can crash."

"If you can already run code on a system then you could do a zillion more useful things than crash it," adds Kristensen. "There are also many ways in which to crash a system if you can run code. Thus it is hard to see what's new here, except that blue screen of death is quite rare these days unless you have malware or a buggy hardware driver."

2X, which reckons that exploiting the flaw would be straightforward, has notified Microsoft about the vulnerability.

"With just a few lines of code an application can be created that will crash the whole Windows system," it said. "This flaw can be easily used inside malicious applications to generate a Denial of Service attack. The problem can be easily corrected within the OS code by validating the arguments passed to the API."

The warning from 2X follows just weeks after UK security firm PrevX wrongly blamed a Black Screen of Death problem on a recent Windows update back in December. Blue screen problems some experienced after applying Microsoft updates earlier this month were later put down to the presence of a rootkit on affected systems.

With this recent history in mind, it's perhaps best to wait for Microsoft's response rather than rushing to judgement on 2X's advisory press release. ®

Mobile application security vulnerability report

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.