Microsoft has gone public to warn about a zero-day vulnerability - TopicsExpress



          

Microsoft has gone public to warn about a zero-day vulnerability in the Windows XP kernel. Apparently, the bug, dubbed CVE-2013-5065, is being exploited in the wild, though details of exactly how, where, by whom and to what effect are not known. That makes it rather hard to decide exactly how to respond, but heres what we know so far: The bug is in the NDPROXY.SYS driver, which co-ordinates the operation of Microsofts Telephony API (TAPI). The exploit doesnt allow remote code execution on its own, only an elevation of privilege (EoP). The vulnerability exists in Windows XP and Server 2003 only. No formal patch or Fixit has been published yet. A simple registry tweak can immunise an XP computer against the vulnerability. The registry tweak has some side-effects you need to know about.
Posted on: Fri, 29 Nov 2013 19:08:25 +0000

Trending Topics



Recently Viewed Topics




© 2015