The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  x64 Driver Signing Update
Time: 08:14 EST/13:14 GMT | News Source: Microsoft | Posted By: Jonathan Tigner

Hi, it’s Scott Field, Windows Security Architect, again. Microsoft recently became aware of a third party kernel mode driver named “Atsiv” which provides a deliberate means of loading code that conflicts with the Kernel Mode Code Signing (KMCS) policy included in Windows Vista x64 editions. In Windows Vista x64 editions, the default KMCS policy is to only allow code to load into the kernel if it has been digitally signed with a valid code signing certificate.

The Atsiv driver also provides a means to load unsigned kernel mode code in a manner that is not visible through operating system provided API interfaces (such as the EnumDeviceDrivers() API), and this may allow the code to hide from view of commonly deployed tools. Installing the Atsiv driver requires administrative privileges, so there is no security vulnerability related to the default case in Windows Vista where users run with limited permissions through the User Account Control feature.

Microsoft is committed to protecting its customers from potential as well as actual security threa[t]s; accordingly, we are responding to this issue as follows:

  1. Windows Defender released a signature update on August 2, 2007 that allows detection, blocking, and removal of the current Atsiv driver. Classification of the Atsiv software was done in accordance with the objective criteria used by the Windows Defender team to assess the characteristics of potentially unwanted software.
  2. Certificate revocation has occurred as of August 2, 2007. Microsoft has worked with partners in the code signing certification authority ecosystem to assess the Atsiv issue. VeriSign has revoked the code signing key used to sign the Atsiv kernel driver, which means the code signing key will no longer be considered valid.
  3. The security team at Microsoft is investigating adding the revoked key to the kernel mode code signing revocation list, as an additional defense in depth measure. The kernel mode revocation mechanism requires a system reboot in order for the new revocation list to take effect, which is consistent with other Microsoft updates which require and subsequently trigger a reboot.

Write Comment
Return to News

  Displaying 576 through 579 of 579
Prev | First
  The time now is 8:38:22 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/23/2025 12:45:56 AM
https://moanio.com/video.php?id=4588
https://moanio.com/video.php?id=5590
https://moanio.com/video.php?id=2122
https://moanio.com/video.php?id=2745
https://moanio.com/video.php?id=4267
https://moanio.com/video.php?id=664
https://moanio.com/video.php?id=2331
https://moanio.com/video.php?id=1174
https://moanio.com/video.php?id=4309
https://moanio.com/video.php?id=5313

#577 By 4240821 (82.115.4.230) at 7/24/2025 12:55:32 AM
https://moanio.com/video.php?id=2664
https://moanio.com/video.php?id=3913
https://moanio.com/video.php?id=3746
https://moanio.com/video.php?id=2427
https://moanio.com/video.php?id=540
https://moanio.com/video.php?id=2021
https://moanio.com/video.php?id=2439
https://moanio.com/video.php?id=1922
https://moanio.com/video.php?id=2842
https://moanio.com/video.php?id=3087

#578 By 4240821 (82.115.4.230) at 7/26/2025 5:24:16 AM
https://moanio.com/video.php?id=3441
https://moanio.com/video.php?id=5544
https://moanio.com/video.php?id=1199
https://moanio.com/video.php?id=3116
https://moanio.com/video.php?id=4871
https://moanio.com/video.php?id=3740
https://moanio.com/video.php?id=2392
https://moanio.com/video.php?id=3236
https://moanio.com/video.php?id=4537
https://moanio.com/video.php?id=496

#579 By 4240821 (82.115.4.230) at 7/26/2025 10:46:07 AM
https://moanio.com/video.php?id=383
https://moanio.com/video.php?id=5444
https://moanio.com/video.php?id=4712
https://moanio.com/video.php?id=4864
https://moanio.com/video.php?id=4645
https://moanio.com/video.php?id=3209
https://moanio.com/video.php?id=3117
https://moanio.com/video.php?id=3546
https://moanio.com/video.php?id=1991
https://moanio.com/video.php?id=204

Write Comment
Return to News
  Displaying 576 through 579 of 579
Prev | First
  The time now is 8:38:22 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *