Feeds

MS virtualisation bug dodges defences

Redmond downplays virtual PC vuln

Next gen security for virtualised datacentres

A newly discovered flaw in Microsoft's virtualisation technologies creates a potential mechanism for hackers to sidestep security defences.

The unpatched vulnerability creates a possible route around security threat mitigation technologies such as Data Execution Prevention (DEP), Safe Exception Handlers (SafeSEH) and Address Space Layout Randomization (ASLR). The security bypass bug affects Virtual PC but not Microsoft virtualisation products based on Redmond's Hyper-V enterprise-class server technology.

The shortcoming, discovered by Core Security, creates a way for hackers to attack applications provided they are running on a virtual PC. The same applications could not be hit in the same way if they were running on a standard PC or server.

Core went public with the publication of an advisory and proof-of-concept code on Tuesday after back-and-forth discussions with Microsoft over seven months reached an impasse. The security firm reckons the unpatched bug, which involves memory management of Microsoft's Virtual Machine Monitor, opening the way to all sorts of potential problems for systems running Windows Virtual PC, Microsoft Virtual PC 2007 and Virtual Server 2005.

Redmond, by contrast, argues the alleged bug discovered by Core only offers a mechanism to "exploit security vulnerabilities already present on the system, rather than an actual vulnerability", security blogger Ryan Nardine reports.

Windows 7 uses Virtual PC technology to provide backward compatibility with older apps via XP Mode. Microsoft continues to say the use of this technology is safe, as explained in much more depth in a post on Redmond's security response blog here. ®

The essential guide to IT transformation

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Microsoft: Azure isn't ready for biz-critical apps … yet
Microsoft will move its own IT to the cloud to avoid $200m server bill
Death by 1,000 cuts: Mainstream storage array suppliers are bleeding
Cloud, all-flash kit, object storage slicing away at titans of storage
US regulators OK sale of IBM's x86 server biz to Lenovo
Now all that remains is for gov't offices to ban the boxes
Oracle reveals 32-core, 10 BEEELLION-transistor SPARC M7
New chip scales to 1024 cores, 8192 threads 64 TB RAM, at speeds over 3.6GHz
VMware vaporises vCHS hybrid cloud service
AnD yEt mOre cRazy cAps to dEal wIth
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?