Microsoft's attempts to provide compatibility for older applications in its forthcoming Windows Vista operating system is opening the door for attackers, security vendor Symantec alleged in a study about the software's user account protection scheme.
Matthew Conover, a principal security researcher with Symantec, wrote in a whitepaper that he " expects several […] privilege escalation vulnerabilities to be discovered."
"Windows Vista's developers had to choose the best way to improve the overall security model while still retaining the most backward compatibility. While most of their decisions seem reasonable, two particular decisions lead to several seemingly intractable implementation flaws."
|