7 Month Vulnerability in Windows Virtual PC
From Mourad Ben Lakhoua
Core Security Technologies (CST) has discovered a critical vulnerability in windows virtual PC allows an attacker to bypass security measures and run a malicious code on the guest machine.
The concerned platform for this vulnerability is Virtual PC 2007, Virtual PC 2007 SP1, Windows Virtual PC, Virtual Server 2005 and Virtual Server 2005 R2 SP1.
The flaw lies in the management memory level (Virtual Machine Monitor).
By leveraging this vulnerability it is possible to bypass security mechanisms of the operating system such as Data Execution Prevention (DEP), Safe Structured Error Handling (SafeSEH) and Address Space Layout Randomization (ASLR) designed to prevent exploitation of security bugs in applications running on Windows operation systems…
Continued: https://www.infosecisland.com/blogview/3352-7-Month-Vulnerability-in-Windows-Virtual-PC.html
All content from Information-Security-Resources.com will begin migrating to the Infosec Island Network:
We are pleased to announce that Infosec Island™ has acquired www.information-security-resources.com, one of the leading online news portals addressing security issues.
The two infosec communities will continue to be operated separately while ISR’s content is gradually migrated to the Infosec Island framework by mid-year.
Don’t miss out on your opportunity to win one of over $10k in service prizes in the Infosec Island Q1 Membership Drive!
Only completed profiles are automatically entered into the drawing. Registration is quick - it takes less than five minutes to complete.
Prizes include:
• The Grand Prize is a FREE core server license, including maintenance, of the Grid Data Security’s Enhanced Authentication Solution from SyferLock™. This prize has a value of up to $10,000.
• Second Prize – The member winning second prize will receive two myKryptofon security software products from I.D. Rank Security, valued at $690.
• Third Prize – Two third prize winners will receive an EncryptStick™ software application download from Onix International Inc.
Register now and win! https://www.infosecisland.com/
We are also seeking active security bloggers and forum moderators - a great way to increase your exposure and generate more business opportunities for your company.
Contact Anthony through your Island email account, or directly at afreed@WireHeadSecurity.com for more details!
Infosec Island is committed to serving the needs of SMBs and mid-market enterprises across many industries, as well as nonprofits, government agencies and educational organizations and the infosec community at large.
Copyright © 2009 - 2010 WireHead Security, LLC. All rights reserved.
* * *
Stay Informed With ISR News Alerts:
* * *
Follow us on Twitter
Filed under: Cloud computing, D&O Liability, Financial, Government, Infosec Island Network, Insider Threat, Internet Security Alliance, Military, PCI, Sarbanes-Oxley, due diligence, hackers, healthcare, identity-theft, malware, national security, privacy, reach, virtualization
Comments
Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!













