| |
|

|
|
User Controls
|
|
New User
|
|
Login
|
|
Edit/View My Profile
|
|

|
|

|
|

|
|
ActiveMac
|
|
Articles
|
|
Forums
|
|
Links
|
|
News
|
|
News Search
|
|
Reviews
|
|

|
|

|
|

|
|
News Centers
|
|
Windows/Microsoft
|
|
DVD
|
|
ActiveHardware
|
|
Xbox
|
|
MaINTosh
|
|
News Search
|
|

|
|

|
|

|
|
ANet Chats
|
|
The Lobby
|
|
Special Events Room
|
|
Developer's Lounge
|
|
XBox Chat
|
|

|
|

|
|

|
|
FAQ's
|
|
Windows 98/98 SE
|
|
Windows 2000
|
|
Windows Me
|
|
Windows "Whistler" XP
|
|
Windows CE
|
|
Internet Explorer 6
|
|
Internet Explorer 5
|
|
Xbox
|
|
DirectX
|
|
DVD's
|
|

|
|

|
|

|
|
TopTechTips
|
|
Registry Tips
|
|
Windows 95/98
|
|
Windows 2000
|
|
Internet Explorer 4
|
|
Internet Explorer 5
|
|
Windows NT Tips
|
|
Program Tips
|
|
Easter Eggs
|
|
Hardware
|
|
DVD
|
|

|
|

|
|

|
|
Latest Reviews
|
|
Applications
|
|
Microsoft Windows XP Professional
|
|
Norton SystemWorks 2002
|
|

|
|
Hardware
|
|
Intel Personal Audio Player
3000
|
|
Microsoft Wireless IntelliMouse
Explorer
|
|

|
|

|
|

|
|
Site News/Info
|
|
About This Site
|
|
Affiliates
|
|
ANet Forums
|
|
Contact Us
|
|
Default Home Page
|
|
Link To Us
|
|
Links
|
|
Member Pages
|
|
Site Search
|
|
Awards
|
|

|
|

|
|

|
|
Credits
©1997/2004, Active Network. All
Rights Reserved.
Layout & Design by
Designer Dream. Content
written by the Active Network team. Please click
here for full terms of
use and restrictions or read our
Privacy Statement.
|
|
|
 |
|
 |
|
 |
| Time:
09:46 EST/14:46 GMT | News Source:
ActiveWin.com |
Posted By: Todd Richardson |
|
There is a flaw in the way that Utility Manager handles Windows messages. Windows messages provide a way for interactive processes to react to user events (for example, keystrokes or mouse movements) and communicate with other interactive processes. A security vulnerability results because the control that provides the list of accessibility options to the user does not properly validate Windows messages sent to it. It's possible for one process in the interactive desktop to use a specific Windows message to cause the Utility Manager process to execute a callback function at the address of its choice. Because the Utility Manager process runs at higher privileges than the first process, this would provide the first process with a way of exercising those higher privileges.
|
| |
|
|
 |
|