Login    
   Windows Server to Workstation
   Convert Windows Server 2008/2008 R2/2012 to a Workstation!
    Register FAQ  •  Search    
It is currently Sun May 26, 2013 6:33 am

All times are UTC [ DST ]




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: 64-bit O/S & Virtualization SW Vulnerable to Attacks
PostPosted: Thu Jun 14, 2012 7:56 pm 
Offline
Win2008Workstation Super Member
Win2008Workstation Super Member

Joined: Sun Jun 13, 2010 2:55 am
Posts: 166
Hi !

"64-bit Operating Systems, Virtualization Software Vulnerable to Privilege Escalation Attacks on Intel CPUs

Some 64-bit operating systems and virtualization software programs are vulnerable to local privilege escalation attacks when running on Intel processors (CPUs), the U.S. Computer Emergency Readiness Team (US-CERT) said in a security advisory on Wednesday.

The vulnerability is identified as CVE-2012-0217 and stems from the way Intel CPUs have implemented the SYSRET instruction in their x86-64 extension, known as Intel 64.
Attackers could exploit the vulnerability to force Intel CPUs to return a general protection fault in privileged mode.
This would allow them to execute code with kernel privileges from a least-privileged account, or to escape from a virtual machine and gain control of the host operating system.

The vulnerability can only be exploited on Intel CPUs when the Intel 64 extension is in use.
This means that 32-bit operating systems or virtualization software are not vulnerable.
Some of the operating systems confirmed as vulnerable so far include x64-based versions of Windows 7 and Windows Server 2008 R2.
The VMWare security response team confirmed that VMware's hypervisor does not make use of the SYSRET instruction and is,
therefore, not vulnerable to this attack, US-CERT said.
Most of the affected vendors have released security patches to address this vulnerability and users are advised to install them as soon as possible.

Microsoft addressed it on Tuesday as part of its MS12-042 security bulletin."

http://www.pcworld.com/businesscenter/article/257634/64bit_operating_systems_virtualization_software_vulnerable_to_privilege_escalation_attacks_on_intel_cpus.html

So if you haven´t already downloaded the latest security-updates from MS, then it´s a VERY good idea to do it !

Update: While editing the text before posting i made some errors, qoutation marks and the link to the source was missing.
I have now corrected the text.

_________________
Security: USER-account, EAM-full, System Center 2012 Endpoint Protection,
Windows FW, Comodo D+, WinPatrol +, HOSTS-file, UAC (max)
Firefox with Noscript, AD-Block & DoNotTrackPlus, working "main CPU" & "2 optical input units".


 Profile  
 Post subject: Re: 64-bit O/S & Virtualization SW Vulnerable to Attacks
PostPosted: Fri Jun 15, 2012 10:23 am 
Offline
Win2008Workstation Super Member
Win2008Workstation Super Member

Joined: Sun Jun 13, 2010 2:55 am
Posts: 166
Update: While editing the text before posting i made some errors, qoutation marks and the link to the source was missing.
I have now corrected the text.

_________________
Security: USER-account, EAM-full, System Center 2012 Endpoint Protection,
Windows FW, Comodo D+, WinPatrol +, HOSTS-file, UAC (max)
Firefox with Noscript, AD-Block & DoNotTrackPlus, working "main CPU" & "2 optical input units".


 Profile  
 Post subject: Re: 64-bit O/S & Virtualization SW Vulnerable to Attacks
PostPosted: Sat Jun 16, 2012 1:03 am 
Offline
Win2008Workstation Expert
Win2008Workstation Expert

Joined: Sat Apr 10, 2010 8:56 am
Posts: 554
Interesting read.

It just goes to show you that hackers adopt their attack strategies toward the most popular trend in IT. Remember when Android and iPhone were new? How long before we saw a butt load of malware infecting a rooted android phone? Nothing has changed with virtualization. Now that this virtualization craze has began to get more popular hackers are switching their attention to finding loopholes in virtualization.

_________________
Image


 Profile  
 Post subject: Re: 64-bit O/S & Virtualization SW Vulnerable to Attacks
PostPosted: Sat Jun 16, 2012 11:53 am 
Offline
Win2008Workstation Expert
Win2008Workstation Expert
User avatar

Joined: Thu Feb 05, 2009 11:27 am
Posts: 365
I agree too.

Very interesting post. TY Hack. ;)

Visualization is democratic now because basically everybody has a 4 Core CPU and therefor uses a x64 OS and then can run VM's.

Some years ago that was not the case as we can all remember our old computers.

In anyway a good post and article too.

N ;)

_________________
|"It's a basic truth of the human condition that everybody lies. The only variable is about what."|


 Profile  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
phpBB skin developed by: John Olson
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
[ Time : 0.048s | 11 Queries | GZIP : Off ]