PDA

View Full Version : MS Virtual PC Flaw Defeats Windows Defenses



wraggster
March 17th, 2010, 21:55
An exploit writer at Core Security Technologies has discovered a serious vulnerability that exposes users of Microsoft's Virtual PC virtualization software to malicious hacker attacks. The vulnerability, which is unpatched, essentially allows an attacker to bypass several major security mitigations — DEP, SafeSEH and ASLR — to exploit the Windows operating system. As a result, some applications with bugs that are not exploitable when running in a not-virtualized operating system are rendered exploitable if running within a guest OS in Virtual PC.

http://tech.slashdot.org/story/10/03/16/1939227/MS-Virtual-PC-Flaw-Defeats-Windows-Defenses