July 24, 2006 7:54 PM PDT

Symantec continues Vista bug hunt

After poking around the Windows Vista networking stack, Symantec researchers have tried out privilege-escalation attacks on an early version of the Windows XP successor.

In a second report on Vista, Symantec takes on a security feature called User Account Control (UAC), in the operating system. The feature runs a Vista PC with fewer user privileges to prevent malicious code from being able to do as much damage as on a PC running in administrator mode, a typical setting on Windows XP.

"We discovered a number of implementation flaws that continued to allow a full machine compromise to occur," Matthew Conover, principal security researcher at Symantec, wrote in the report titled "Attacks against Windows Vista's Security Model." The report was made available to Symantec customers last week and is scheduled for public release sometime before Vista ships, a Symantec representative said Monday.

Conover looked at the February preview release of Vista. The report describes how an attacker could commandeer a Vista PC with Internet Explorer 7, the reinforced version of Microsoft's Web browser. The final version of Vista is not expected to be broadly available until January.

The attack starts out by planting a malicious file on a Vista PC when a rigged Web site is visited. The placing of the file involves using a specially crafted Web program called an ActiveX control, which exploits a security hole. The report then describes how the malicious program could gain privileges and ultimately give an attacker full control of the PC.

"The triviality of this privilege escalation...foreshadows the grave difficulty that the Windows Vista security model will have enforcing the separation between low and medium integrity level under the same user account," Conover wrote.

Microsoft has already resolved most of the issues identified in the Symantec report, a representative for the Redmond, Wash., company said in a statement. "Highlighting issues in early builds of Windows Vista does not accurately represent the quality and depth of the final functionality of User Account Control," the representative said.

Additionally, Microsoft said the Symantec research assumes that the user is logged in with an administrator account, a setting Microsoft does not recommend. Instead, the software maker advises the use of standard user accounts, which will require users to enter a password to gain administrator-level privileges for certain tasks--to install software, for example.

Microsoft has pitched Vista as its most secure operating system ever. UAC and Internet Explorer 7 are two of the key ingredients to deliver that security.

The report on UAC is the second of three reports Symantec plans to release on Windows Vista. A first report, on new Vista networking technology, was publicly released last week. A third report, examining the Vista core, or kernel, is scheduled to be published this week on Symantec's DeepSight security intelligence service.

Traditionally allies, Microsoft and Symantec are now going head-to-head in the security arena. In late May, Microsoft introduced Windows Live OneCare, a consumer security package, and the software giant is readying an enterprise desktop security product. Symantec has also sued Microsoft, alleging misuse of data storage technology it licensed to the company.

"Symantec continuously researches and analyzes new technologies," said Pamela Reese, a Symantec spokeswoman. "Even with the understanding that the issues discussed in this research will likely be resolved before Windows Vista is shipped, Symantec has opted to make this research public because of the public interest in Vista."

But telling the world at large about vulnerabilities in an operating system that won't ship for a while doesn't help anybody, noted John Pescatore, a Gartner analyst. Though it may help Symantec's marketing machine. "They want to sell desktop security software even when Vista comes out," Pescatore said.

Additionally, security companies benefit from getting their name associated with finding vulnerabilities. "It helps people trust them as a security company," Pescatore said.

Symantec said it is encouraged to see that Microsoft is taking care of the basics by improving the security of its newest operating system. "However, Symantec feels that customers are safer if they can exercise their choice to use the security capabilities offered by Symantec and others," Reese said.

See more CNET content tagged:
Symantec Corp., Microsoft Windows Vista, Microsoft Internet Explorer 7, security, representative

Add a Comment (Log in or register) 13 comments
Microsoft does not recommend Admin accounts?
by Take the Red Pill July 24, 2006 8:14 PM PDT
"Microsoft said the Symantec research assumes that the user is logged in with an administrator account, a setting Microsoft does not recommend. Instead, the software maker advises the use of standard user accounts, which will require users to enter a password to gain admin-level privileges"

I agree that using an Admin account is unnecessary and a security risk, so WHY does Vista automatically setup the first user created as an administrator (at least in the latest public beta)?

I'm not referring to the actual "Administrator" login, I mean the first USER, created during installation, is setup with Admin access. Doesn't that defeat the whole purpose of getting away from using Admin and undermine their security efforts?
Reply to this comment View all 2 replies
Symantec spreading FUD
by Jamie_Foster July 24, 2006 11:43 PM PDT
Symantec is trying to discredit MS over security. The problem is that Norton Security totally sucks. Check out the criticisms of Norton at Wikipedia. CNET readers should try etrust EZ antivirus from CA, free AVG, AntiVir, or avast! or ClamWin or MS OneCare. Norton is really slow, bloated, eats up RAM and CPU power. It is buggy and like all symantec products doesn't unistall properly, hence the need for the SymNRT tool. In short Norton sucks and is the worst product on the market, it is only for suckers. Check out Amazon.co.uk if you don't believe me. With new competition from MS, Symantec will finally get wiped out.
Reply to this comment View all 3 replies
Bug Hunt?
by als July 25, 2006 7:06 AM PDT
Symantec needs to do a bug hunt through their own stuff! What utter garbage software they foist on the uninformed public.
Reply to this comment
Good for vista
by Tanjore July 25, 2006 8:19 AM PDT
Its good for microsoft as vista is under microscope. This will force microsoft fix issues and hopefully deliver a solid product.
Reply to this comment
Face the facts
by Michael Grogan July 25, 2006 8:20 AM PDT
M$ has always sucked at security and they always will. Symantec used to be the best but they suck as well now. At any rate, I'll bet dollars against doughnuts that Vista will be clobbered by some virus, worm or other malicious code before it's out a month.
Reply to this comment
Symantec
by lolio July 29, 2006 9:40 PM PDT
This company is a joke, with all of their bloatware they sell, they should fix their own garbage! I have and will continue to remove any Symantec products from all my customers computers (which we know is no easy task)!!!
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Timing rumors surface for AMD plant spin-off

    Rumors persist that Advanced Micro Devices is planning to spin off all or part of its manufacturing operations.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Digital Noise: Music and Tech

    Was 1980s music that bad?

    NPR asks listeners which year featured the best music, and the 1980s emerge as a bleak era. Personally, the '80s figure prominently in my collection, but well behind the 1970s.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    Michael Moore plans Net-only film premiere

    Filmmaker plans to premiere his latest documentary exclusively on the Internet for free, forgoing the traditional theatrical release.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    What you can--and can't--find about Palin on the Internet

    John McCain's choice of Sarah Palin as a running mate has inspired a wealth of creativity on the Internet.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Crossfade

    Ying Yang Twins, 'Look Back At It': Free MP3 of the Day

    This amped-up duo gets the party started with a mix of crisp, Southern hip-hop beats and shout-along rhymes. Download a free MP3 of "Look Back At It" courtesy of CNET Download Music.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.