Linked by Thom Holwerda on Mon 18th Jan 2010 22:00 UTC
Thread beginning with comment 404834
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/22/13 22:23 UTC
Linked by Thom Holwerda on 05/22/13 13:38 UTC
Linked by Thom Holwerda on 05/22/13 13:30 UTC, submitted by JRepin
Linked by Thom Holwerda on 05/21/13 22:06 UTC
Linked by Thom Holwerda on 05/21/13 21:45 UTC
Linked by Thom Holwerda on 05/21/13 15:53 UTC
Linked by Thom Holwerda on 05/20/13 22:43 UTC
Linked by Thom Holwerda on 05/20/13 21:50 UTC
Linked by Thom Holwerda on 05/19/13 23:15 UTC
Linked by Thom Holwerda on 05/19/13 23:11 UTC, submitted by Drumhellar
More News »
Sponsored Links



Member since:
2005-07-11
Well, those people are the CTO of McAfee and the white hat security researcher who's actually trying to expand upon the exploit, so they shouldn't be dismissed outright. Granted, the CTO points to a YouTube video on how McAfee software can block this exploit, so you could argue he's got an agenda. But that doesn't change the fact that the researcher has been able to get as far as read-only access to the system through IE7 on Vista. Hopefully, protected mode won't be easy to break out of, but still Microsoft needs to patch this ASAP. Mechanisms like DEP and protected mode are meant to be extra layers to mitigate the impact of exploits, but not long term substitute solutions. (Although after this incident, I would like to see an additional patch to opt-in IE7 to DEP by default; it probably couldn't be done in IE6 due to the same compatibility issue that have kept them from upgrading to newer versions.)