Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft reacts to kernel hacks, updates Vista's defenses

Patches PatchGuard to keep 64-bit Vista safer from unsigned code

August 15, 2007 12:00 PM ET

Computerworld - Microsoft Corp. quietly beefed up a key defensive feature of 64-bit Windows Vista yesterday to better protect the operating system against hacks that have plagued it for weeks.

The update to Vista's Kernel Patch Protection, a.k.a. PatchGuard, was issued through Windows Update as a high-priority download, but not as a patch per se. Microsoft, in fact, denied that it was a security fix. "While this update adds additional checks to the Kernel Patch Protection system, it does not involve a security vulnerability," an advisory posted yesterday by the Microsoft Security Response Center (MSRC) stated. "The update does increase the reliability, performance, and resiliency provided by Kernel Patch Protection."

Although the update targets all 64-bit editions of Windows, it's Vista that stands out by reason of recent events. Since late July, a pair of utilities have sidestepped a crucial Vista security feature that requires drivers to be signed by a valid digital certificate. Both utilities piggybacked unsigned code onto a legitimate driver to get the former past Vista's defenses and into the kernel.

First off the mark four weeks ago was Australian developer Linchpin Labs, which released Atsiv (Vista spelled backward), a utility that allowed users to load unsigned drivers to the Vista kernel. Within days, Microsoft had the certificate revoked, forcing Linchpin to throw in the towel.

Next, Canadian researcher Alex Ionescu last week took advantage of a flaw in a Vista video driver from Advanced Micro Devices Inc.'s ATI Technologies unit to unveil Purple Pill, another utility that allowed unsigned drivers to be loaded into the kernel. Ionescu quickly pulled Purple Pill once he realized that the ATI driver had not been patched.

"[Purple Pill] had embedded in it an ATI signed driver that would be dropped to disk and loaded (a similar approach to Atsiv)," said Symantec Corp. analyst Ollie Whitehouse in a posting to the company's security blog last week. "However it would appear that this signed driver contained a design error which allows you to use it to load any arbitrary driver even if they are not signed."

For its part, ATI refreshed its Catalyst video driver for Vista on Monday to patch against a repeat of Purple Pill, fulfilling a promise made earlier by AMD in a statement posted by ZDNet blogger Ryan Naraine.

While Catalyst 7.8 may have plugged the hole in ATI's driver, more driver vulnerabilities or design flaws would likely be found, or others would take the Atsiv approach and pay the money for a certificate. "Let's hope Microsoft steps in and uses Windows Update as an upgrade mechanism for them," Whitehouse said in a post yesterday.



Jump to comments

Microsoft

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...