Results 1 to 3 of 3

Thread: Win7 and Vista sidebar/gadget vulnerability

  1. #1
    Senior Moment blueball's Avatar
    Join Date
    Aug 2005
    Location
    Edinburgh
    Posts
    2,246
    Thanks
    680
    Thanked
    335 times in 263 posts
    • blueball's system
      • Motherboard:
      • Gigabyte P35-DQ6
      • CPU:
      • Q9650 (4 x 3GHz Cores)
      • Memory:
      • 8Gb (4 x 2Gb) Kingston PC2-6400 DDR2
      • Storage:
      • 1TB RAID 0 (2 x Samsung F1 500Gb)
      • Graphics card(s):
      • Gigabyte 2GB GeForce GTX 670 OC Windforce 3X
      • PSU:
      • CoolerMaster Silent Pro 850W
      • Case:
      • Lian-Li A17
      • Operating System:
      • Win 7 Ultimate x64
      • Monitor(s):
      • 24" Samsung T240 (1920x1200)
      • Internet:
      • Virgin Media 50Mb

    Win7 and Vista sidebar/gadget vulnerability

    Taking a sledgehammer to crack a nut?
    ===============================================================


    This is a security bulletin from the MCT-SafeComputing-List.
    A copy of the text of this email for verification - which may include
    further updates is at:
    http://safecomputing.open.ac.uk/latest_bulletins.htm

    Bulletin ID (also shown on web version): DCLR-8W5B4A

    -----------------------------------------------------------------------------------------------
    B U L L E T I N
    Microsoft is proceeding with plans to remove the Windows 'Sidebar and
    Gadget' platform from Windows Vista and Windows 7 because it allegedly
    contains serious security vulnerabilities which will be disclosed at a
    forthcoming security conference.

    Microsoft has said that it has discovered that some Vista and Win7 gadgets
    don’t adhere to secure coding practices and should be regarded as causing
    risk to the systems on which they’re run. They intend to provide a 'Fix it'
    utility to help system administrators to disable Gadgets and the Sidebar
    across their enterprises.

    if an attacker successfully exploited a Gadget vulnerability they could run
    arbitrary code in the context of the current user

    Domestic users will also be affected by vulnerabilities about to be
    revealed in the Sidebar and Gadgets interface, and may decide not to use
    them as a precaution. A link to the Microsoft FixIt utility which will
    disable the interface is shown below

    The Sidebar and Gadgets interface will not be present in Windows 8 when it
    is released.
    -------------------------------------------------------------------------------------------------------------------

    W E B L I N K S
    ZDNet:
    http://www.zdnet.com/security-flaws-...ts-7000000724/

    Ars Technica:
    http://arstechnica.com/security/2012...ndows-gadgets/

    The Verge:
    http://www.theverge.com/2012/7/11/31...-vulnerability

    Microsoft Gadgets:
    http://windows.microsoft.com/en-us/w...dgets-overview

    Microsoft Bulletin:
    http://technet.microsoft.com/en-us/s...19662#section1
    Microsoft FixIt: http://support.microsoft.com/kb/2719662
    -------------------------------------------------------------------------------------------------------------------
    Rgds,

    BB
    Hexus Trust here and here

  2. #2
    Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    3,744
    Thanks
    426
    Thanked
    62 times in 45 posts
    • Apex's system
      • Motherboard:
      • Asus F1A55-M
      • CPU:
      • AMD A6-3670K APU
      • Memory:
      • 16 GiB
      • Storage:
      • 5.0 TiB
      • Graphics card(s):
      • ATI (ASUS) HD6850 1024MiB
      • PSU:
      • 750
      • Case:
      • SilverStone TJ08-E
      • Operating System:
      • Windows 7 64Bit
      • Monitor(s):
      • Dell U2410 24"
      • Internet:
      • 20Mb nTL Cable

    Re: Win7 and Vista sidebar/gadget vulnerability

    So insted of fixing it they are removing it, way to go M$.

  3. #3
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    5,016
    Thanks
    965
    Thanked
    429 times in 372 posts
    • Phage's system
      • Motherboard:
      • MSi Z77 GD65
      • CPU:
      • 3570k @ 4.4Ghz
      • Memory:
      • 8Gb HyperX RAM
      • Storage:
      • Samsung 830 256Gb + 1Tb Hitachi @ 7200
      • Graphics card(s):
      • Gigabyte 7970 3Gb
      • PSU:
      • True Power 750w
      • Case:
      • Fractal R3
      • Operating System:
      • W7 64
      • Monitor(s):
      • Dell U2412M

    Re: Win7 and Vista sidebar/gadget vulnerability

    Reading that it seems that vulnerabilities would be introduced by gadgets written by 3rd parties. Accordingly, they are assuming the lowest common denominator and allowing the public to remove the functionality if they feel it's necessary.

    I'm OK with that.
    Society's to blame,
    Or possibly Atari.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •