0
0 0 0 0 0 0
0
0 0
Message
0ID:
0PW:
0forget pwd? | Join now
0
0
0
Online: Member 2 Guest 2
0
0
0


0
MSN: test104tw@hotmail.com
0
0
  • Microsoft 70-502 Q & A 115 Questions. (2012/2/7)
  • CISCO 642-611 Q & A 101 Questions. (2012/2/7)
  • IBM 000-R01 Q & A 326 Questions. (2012/2/6)
  • Check Point 156-915-65 Q & A 127 Questions. (2012/2/6)
  • Microsoft 70-515 Q & A 124 Questions. (2012/2/2)
  • SUN 310-230 Q & A 175 Questions. (2012/2/2)
  • IBM 000-206 Q & A 107 Questions. (2012/2/1)
  • EC-Council EC1-350 V7 Q & A 261 Questions. (2012/2/1)
  • IBM 000-435 Q & A 156 Questions. (2012/1/19)
  • HP HP0-J12 Q & A 120 Question. (2012/1/19)
  • Oracle 1Z0-053 Q & A 200 Questions. (2012/1/18)
  • Microsoft 70-642 Q & A 190 Questions. (2012/1/18)
  • LPIC 117-102 Q & A 126 Questions. (2012/1/17)
  • Microsoft 70-640 Q & A 331 questions. (2012/1/17)
  • Microsoft 70-528 Q & A 111 Questions. (2012/1/16)
  • IBM 000-315 Q & A 106 Questions. (2012/1/16)
  • IBM 000-150 Q & A 120 Questions. (2012/1/13)
  • Microsoft 70-632 Q & A 135 Questions. (2012/1/13)
  • EC-Council EC0-350 Q & A 339 Questions. (2012/1/11)
  • CWNP PW0-104 Q & A 110 Questions. (2012/1/11)
0
0
0
Name:
E-mail:
Telephone:
CheckCode: 0

Suggestions & Questions:

 

0
0
0
::Visitors::
000230927

 

 

Microsoft issues advisory for Windows display driver flaw[2010/5/21]
[TextSizeBig Middle Small][Print]
Microsoft has issued a security advisory, Tuesday, warning users of a publicly reported vulnerability in the Windows Canonical Display Driver, a Windows component used to handle graphics and DirectX drawing in games and other software programs.

The vulnerability affects Windows 7 and Windows Server 2008 systems. So far, the biggest risk posed by the vulnerability is a potential to cause a system to crash and restart, Microsoft said.


"We've deduced so far that reliable exploit code is unlikely," wrote Jerry Bryant group manager of Microsoft response communications in the Microsoft Security Response Center Blog. "We're currently developing a security update for Windows that will address the vulnerability."

Microsoft engineers called successful exploitation of the display driver error tricky and said it cannot be exploited remotely. An attacker would need to write executable content to a specific space in kernel memory. Address Space Layout Randomization (ASLR), a security feature enabled by default in Windows Vista, Windows Server 2008 and Windows 7, makes a successful exploitation even more difficult.


The engineers were able to successfully exploit the flaw locally on a Windows 7 64-bit computer with the Aero Glass theme enabled. They warned that there is potential for an attacker to exploit the vulnerability using a malicious image with a third-party image viewer.

As a workaround, Microsoft recommends temporarily disabling the Aero Glass theme.



0