Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Symantec Educates Microsoft on x64 Windows Vista Update

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Symantec Educates Microsoft on x64 Windows Vista Update
LinkBack Thread Tools Display Modes
Old 09-Sep-2007, 10:23 PM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,715
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Symantec Educates Microsoft on x64 Windows Vista Update

Microsoft seems to be in need of some education related to its Windows Update practices and Symantec seems more than happy to oblige it. The issue is related to the 64-bit editions of Windows Vista and the mandatory driver signing mitigation introduced by Microsoft in order to safeguard the operating system's core from unsigned code. All kernel modules on systems running the x64 editions of Windows Vista must feature digital signatures. In the absence of a digital signature, kernel-level software and especially drivers for the x64 operating system will not be able to load. Essentially, driver signing is a mitigation designed to verify the validity of a certain code author and not a security measure, as Microsoft underlined. But while the Redmond company has locked all unsigned code out of the Vista kernel, driver signing is by no means foolproof. And in this context, the feature has generated some interesting circumvention techniques, but also catalyzed the production of software designed to workaround the protection and load unsigned code into the kernel of 64-bit Vista. Case in point, the Purple Pill authored by Alex Ionescu, kernel developer and reverse engineer, following the Atsiv tool, created by Linchpin Labs & OSR. Both programs offer a way to bypass driver signing on 64-bit Windows Vista. But while Atsiv used legitimate certificates that were subsequently revoked, while the tool was blacklisted by Microsoft as potentially unwanted software, the story with Purple Pill is a little different.

Purple Pill in fact involved the use of a vulnerability residing in the ATI Vista x64 Video Driver in order to load unsigned code into the core of the operating system. The tool was taken down by Ionescu as the vulnerability was yet to be patched by AMD ATI. Currently a patch is available via Windows Update for the affected drivers, but is labeled as an optional update by Microsoft.

"It is kind interesting that Microsoft is making the update only ‘optional’. One would think that it would be in Microsoft’s best interests to expedite the deployment and thus ability to remove the vulnerable driver or revoke its signing certificate. I suspect they are being massively cautious as a ‘critical’ update would force everyone to download and reboot (if their machines are configured so). If there were any potential stability issues with the new driver, hosing millions of desktops in one go isn’t probably going to win you any friends," commented Ollie Whitehouse, Architect, Symantec Advanced Threat Research.

The new versions of the ATI video drivers have been made available since last month, and you also can download the 32-bit and the 64-bit versions. The new releases take care of the vulnerability exploited by the Purple Pill.

Still, for the Whitehouse there are a couple of "things still not clear: a) How is Microsoft going to stop the old ATI driver being loaded and exploited by users that do manage to obtain Administrative privileges? b) When is it safe to revoke the signing certificate (I believe it will have used timestamp signing and thus be possible to revoke it only for signed file before a certain date) or add its signature to security software such as antivirus."



------------------


Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 03:29 AM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228