According to a security advisory from Next Generation Security Software (NGSSoftware) of Sutton, England, Microsoft is continuing to certify drivers for network interface cards (NICs) even though they leak data. The vulnerability was first discovered by @stake and revealed in January. At the time, Microsoft promised to include data leak tests in its driver certification process to ensure the vulnerability was fixed.
NGSSoftware only tested two NIC card drivers on Windows Server 2003, the VIA Technologies Rhine II Ethernet controller and the Advanced Micro Devices (AMD) PCNet family, and both were found to be flawed. The cause of the problem is that instead of filling empty space in frames with an unusable string of data (such as all 0s, as specified by the IEEE), the space is filled with real data pulled randomly from the computer.
|