|
 |
dimarts, 26 / desembre / 2006 |
|
|
Ampliant el comentari anterior, el que realment cal conèixer per avaluar la seguretat de Windows no és el fet que s'hagi descobert una vulnerabilitat a Vista sinó aquesta taula que publica SANS Institute:
| Affected |
Known Exploits |
Impact |
Known since
|
ISC rating(*) |
| clients |
servers |
NetrWkstaUserEnum() memory allocation exhaustion
|
Publicly posted exploit |
Remote DoS ?
|
Dec 25th, 2006
|
unkown
|
unknown
|
MessageBox() / csrss double free vulnerability
CVE-2006-6696
|
Publicly posted PoC exploits for XP, 2003 and Vista
MSRC blog
|
Privilege Escalation
|
Dec 15th, 2006
|
Important
|
Less Urgent
|
Office 2004 vulnerabilities (Mac version)
Unspecified vulnerabilites fixed in a accidentally released patch. Patch has been withdrawn after being public and eventually replaced with one without security fixes.
|
Exposed through a patch by Microsoft.
MSRC blog #1 MSRC blog #2
|
unknown
|
Dec 12th, 2006
|
unknown
|
unknown
|
Word unspecified vulnerability #3
CVE-2006-6561
|
Publicly available exploit.
MSRC blog
|
Remote code execution
|
Dec 12th, 2006
|
Critical
|
Important
|
Word unspecified vulnerability #2
CVE-2006-6456
|
MSRC blog #1 MSRC blog #2 Used in targeted attacks
|
Remote code execution
|
Dec 10th, 2006
|
Critical |
Important
|
Word unspecified vulnerability #1
CVE-2006-5994
|
Microsoft Security Advisory 929433 MSRC blog
Used in targeted attacks
|
Remote code execution |
Dec 5th, 2006
|
Critical |
Important
|
RPC in Windows 2000 SP4 UPnP and SPOOLS
CVE-2006-6296 CVE-2006-3644
|
Multiple publicly available exploits.
|
DoS
|
Nov 16th, 2006
|
Less Urgent
|
Important
|
ADODB.Connection ActiveX
CVE-2006-5559
|
MSRC blog
Public DoS exploit.
|
Remote code execution
|
Oct 24th, 2006
|
Critical
|
Important
|
| Workaround: set the killbit for 00000514-0000-0010-8000-00AA006D2EA4 |
Microsoft Windows NAT Helper Components
CVE-2006-5614
|
Publicly available exploit.
|
DoS
|
Oct 20th, 2006
|
Less Urgent
|
Important
|
PowerPoint 2003
CVE-2006-5296
|
MSRC blog #1 MSRC blog #2
Publicly available exploit.
|
DoS
|
Oct 20th, 2006
|
Less Urgent
|
Less Urgent
|
(*): ISC rating
- We use 4 levels:
- PATCH NOW: Typically used where we see immediate danger of exploitation. Typical environments will want to deploy these patches ASAP. Workarounds are typically not accepted by users or are not possible. This rating is often used when typical deployments make it vulnerable and exploits are being used or easy to obtain or make.
- Critical: Anything that needs little to become "interesting" for the dark side. Best approach is to test and deploy ASAP. Workarounds can give more time to test.
- Important: Things where more testing and other measures can help.
- Less urgent: Typically we expect the impact if left unpatched to be not that big a deal in the short term. Do not forget them however.
- The difference between the client and server rating is based on how you use the affected machine. We take into account the typical client and server deployment in the usage of the machine and the common measures people typically have in place already. Measures we presume are simple best practices for servers such as not using outlook, MSIE, word etc. to do traditional office or leaisure work.
- The rating is not a risk analysis as such. It is a rating of importance of the vulnerability and the perceived or even predicted threat for affected systems. The rating does not account for the number of affected systems there are. It is for an affected system in a typical worst-caserole.
- Only the organization itself is in a position to do a full risk analysis involving the presence (or lack of) affected systems, the actually implemented measures, the impact on their operation and the value of the assets involved.
-- Swa Frantzen -- Section 66
|
11:02 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
Tanta gràcia em fan les declaracions del tipus: «Windows Vista és el sistema més segur que hi ha» com les declaracions: «Hi ha un problema de seguretat que afecta a Windows Vista». Els dos casos són declaracions fetes des d'un total desconeixement de la seguretat informàtica i la industria del software (IMHO).
La darrera mostra: Report: More flaws found in Microsoft's Vista
Computer security researchers and hackers have found more flaws in Microsoft's Vista, the long-awaited update to the Windows operating system, according to a report Monday.
One programmer said it was possible to increase a user's privileges on all of the company's recent operating systems, including Vista, while a computer security firm said that it found five other vulnerabilities, including one error in the software code underlying the company's new Internet Explorer 7 browser
The browser flaw means that users could become infected with malicious software simply by visiting a particular Web site, according to the report.
That would make it possible for an attacker to inject rogue software into the Vista-based computer, the paper said, citing executives at Determina, a maker of software intended to protect against vulnerabilities. En la meva opinió, no importa tant saber que *hi ha* problemes de seguretat; el que realment és important és saber quan de temps passa entre el descobriment del problema de seguretat (ja sigui de forma 'reglada' o través d'un 0-day) i la disponibilitat dels mecanismes necessaris per eliminar-lo, habitualment a través d'un pegat. També dono molta importància a la disponibilitat de mecanismes que facilitin una ràpida distribució del pegat.
Evidentment que cal fer tot el possible per evitar, d'entrada, l'existència de problemes de seguretat. Les mesures de prevenció són d'allò més important... però també són igualment importants les mesures de reacció davant situacions que, de forma inevitable, es produiran.
Per tant, l'important no és saber que *avui* Windows Vista té problemes de seguretat, sinó quan de temps passa abans que aquests problemes disposin d'una solució.
|
10:44 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
© Copyright 2000-2006 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
|
|