News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Microsoft/Windows
Average Rating:
Rate this article:  
First Windows 7 Exploit Appears To Evade SDL Process First Windows 7 Exploit Appears To Evade SDL Process
By Jennifer LeClaire
November 13, 2009 10:23AM

    Bookmark and Share
The first zero-day exploit in Windows 7 has been reported by security researcher Laurent Gaffié, who questioned if Microsoft's Secure Development Lifecycle process exists. The Windows 7 exploit appears to take advantage of a bug in the Server Message Block protocol for file sharing. Windows 7 was not patched on Patch Tuesday.
 



Windows Relevant Products/Services 7 escaped the monthly patching process earlier this week, but it didn't escape the notice of hackers. What some security researchers are calling the first zero-day exploit in Windows 7 has been identified and Microsoft Relevant Products/Services is investigating the issue.

Security researcher Laurent Gaffié called Microsoft on the carpet for its Secure Development Lifecycle (SDL) process on Wednesday. Gaffié also published proof-of-concept exploit code that he says will crash both Windows 7 and Windows Server 2008 R2.

"This bug is a real proof that SDL #FAIL," Gaffié wrote in his blog post. "The bug is so noob, it should have been spotted two years ago by the SDL if the SDL had ever existed."

The SMB Relevant Products/Services Flaw

At the core of the vulnerability is the SMB (Server Message Block) protocol, the foundation of Windows file sharing. According to Gaffié, the bug triggers an infinite loop on SMB and can be triggered remotely via Internet Explorer. Gaffié notified Microsoft on Nov. 8 before releasing his proof of exploit on Nov. 11.

When Microsoft released Windows 7 to manufacturing, rumors were rampant about a showstopper bug that could threaten the success of the all-important Vista successor. At that time, technology researchers claimed to have found a bug in the new operating system Relevant Products/Services that causes a massive memory leak and could cause the company to delay the final release. But Microsoft was not able to reproduce the crash.

Other than that, security issues have been nonexistent -- until now. Although Microsoft did have issues with the SMB in the past, security researchers have noted that the SMB vulnerability was difficult to exploit with default firewall conditions. There is a workaround: Blocking ports 135, 139 and 445 on the router or firewall to prevent outside SMB traffic from getting into a system.

Bragging Against Microsoft

Chet Wisniewski, a senior security adviser at Sophos, isn't surprised to see an exploit in Windows 7 so soon after its release. That, he said, is because the Windows code was finalized very early this summer.

"Attackers have had plenty of time to look for holes," Wisniewski said. "This particular flaw was not too difficult to discover, leading the attacker to brag about how stupid it was for Microsoft to have missed it."

At this point, there's no grave danger for Windows 7 users. As Gaffié noted in his disclosure, exploiting the vulnerability can crash a host. That translates to rebooting the computer. Wisniewski noted that the zero-day vulnerability is not in worm form as of yet, and only applies to Windows 7 and Windows 2008 R2. That means it's simply a denial of service Relevant Products/Services at this point.

Will Microsoft issue an out-of-cycle patch? Not unless someone tries to use this to cause a lot of people to complain, Wisniewski said. "The only real way to use it is to spam out a UNC path and trick users into connecting to it," he explained. "It is unlikely, being that no data Relevant Products/Services is lost, and it requires the user to take an action to be affected."

Wisniewski said the author's aggression toward Microsoft is interesting, but aside from that this is simply another everyday denial-of-service vulnerability in Windows.
 

Tell Us What You Think
Your Comment:



Advertisement


 Microsoft/Windows
1.   MS: Windows 7 Doesn't Hurt Battery
2.   Tips for More Windows 7 Productivity
3.   MS: Russian Pirates Scamming Us
4.   Patch Tuesday Will Tie MS Record
5.   Battery Drains Linked To Windows 7


advertisement
Tips for More Windows 7 ProductivityTips for More Windows 7 Productivity
Win 7 is chock-full of unsung features.
Average Rating:
Is Bill Gates Batting for Team China?Is Bill Gates Batting for Team China?
He implies Google is overreacting.
Average Rating:
Rush IE Patch Coming Says MicrosoftRush IE Patch Coming Says Microsoft
Exploit testing tools are being updated.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a new notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.