Microsoft reacts to kernel hacks, updates Vista's defenses
Patches PatchGuard to keep 64-bit Vista safer from unsigned code
August 15, 2007 12:00 PM ETComputerworld - Microsoft Corp. quietly beefed up a key defensive feature of 64-bit Windows Vista yesterday to better protect the operating system against hacks that have plagued it for weeks.
The update to Vista's Kernel Patch Protection, a.k.a. PatchGuard, was issued through Windows Update as a high-priority download, but not as a patch per se. Microsoft, in fact, denied that it was a security fix. "While this update adds additional checks to the Kernel Patch Protection system, it does not involve a security vulnerability," an advisory posted yesterday by the Microsoft Security Response Center (MSRC) stated. "The update does increase the reliability, performance, and resiliency provided by Kernel Patch Protection."
Although the update targets all 64-bit editions of Windows, it's Vista that stands out by reason of recent events. Since late July, a pair of utilities have sidestepped a crucial Vista security feature that requires drivers to be signed by a valid digital certificate. Both utilities piggybacked unsigned code onto a legitimate driver to get the former past Vista's defenses and into the kernel.
First off the mark four weeks ago was Australian developer Linchpin Labs, which released Atsiv (Vista spelled backward), a utility that allowed users to load unsigned drivers to the Vista kernel. Within days, Microsoft had the certificate revoked, forcing Linchpin to throw in the towel.
Next, Canadian researcher Alex Ionescu last week took advantage of a flaw in a Vista video driver from Advanced Micro Devices Inc.'s ATI Technologies unit to unveil Purple Pill, another utility that allowed unsigned drivers to be loaded into the kernel. Ionescu quickly pulled Purple Pill once he realized that the ATI driver had not been patched.
"[Purple Pill] had embedded in it an ATI signed driver that would be dropped to disk and loaded (a similar approach to Atsiv)," said Symantec Corp. analyst Ollie Whitehouse in a posting to the company's security blog last week. "However it would appear that this signed driver contained a design error which allows you to use it to load any arbitrary driver even if they are not signed."
For its part, ATI refreshed its Catalyst video driver for Vista on Monday to patch against a repeat of Purple Pill, fulfilling a promise made earlier by AMD in a statement posted by ZDNet blogger Ryan Naraine.
While Catalyst 7.8 may have plugged the hole in ATI's driver, more driver vulnerabilities or design flaws would likely be found, or others would take the Atsiv approach and pay the money for a certificate. "Let's hope Microsoft steps in and uses Windows Update as an upgrade mechanism for them," Whitehouse said in a post yesterday.
Microsoft
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
