Symantec: Vista's Color-Coded Security Messages Can Be Spoofed
February 28, 2007 9:00 AM ET
A security feature in Microsoft's new Windows Vista operating system that's designed to give IT administrators more control over workers' desktops can be easily fooled by malware because it's effectively color blind, according to a researcher at security software vendor Symantec.
The User Account Control feature in Windows Vista is designed to prevent individuals from making system changes that aren't authorized by their IT departments. The feature is supposed to prevent beguiled workers from installing software that could present a threat to their corporate networks.
If a user attempts such a change, he or she is greeted with an error message bordered in bright red informing them that the move isn't authorized. Notifications for supposedly innocuous changes not requiring administrator approval -- such as activating a driver or other component that is a built-in part of Windows -- are presented within a friendly, light-green border.
The trouble, according to Symantec security researcher Ollie Whitehouse, is that malicious code can "trick" Windows Vista into generating the green notification when it should be holding up the stop sign. "The user is presented with a UAC prompt that [falsely] claims that Microsoft Windows needs to elevate permissions ... not a third-party application," writes Whitehouse, on his blog on Symantec's Web site.
Whitehouse says the problem can occur when users try to activate a part of Windows Vista -- RunLegacyCPLElevated.exe -- that's supposed to make Vista compatible with older Windows Control Panel plug-ins. Files associated with RunLegacyCPL.exe can act as Trojan horses for malware that can then get written to unprotected areas of a user's hard drive after he or she gets the bogus green light.
"Microsoft is saying you should only see [the green dialog box] if the application is part of Windows," Whitehouse writes in his blog entry, which appeared earlier this week. "While it's true that RunLegacyCPLElevated.exe is part of Windows, it isn't true that the arbitrary DLL it loads and executes is," Whitehouse says.
Microsoft, in a best practices guide, concedes that Vista's color-coded warnings aren't a fail safe security measure. "The UAC prompts aren't a direct security boundary -- they don't offer direct protection," says Microsoft. "They do offer you a chance to verify an action before it happens."
|
|
Symantec's Code Red: The Law Enforcement/Anonymous E-Mail Exchange Law enforcement officials negotiated via e-mail for more than two weeks with an Anonymous group member trying to extort $50,000 from Symantec to keep stolen product code off the Internet. |
|
|
How To Sell IT Security Services To Your Customers Cyberattacks can cost a business thousands, even millions, of dollars, and can deal a death blow to some. Here's how IT solution providers can help guard against malicious attacks. |
|
|
Cybersecurity Experts: What They Know Could Scare You A recent report based on interviews with security experts in government, business and academia finds more than half in agreement that a worldwide arms race is taking place in cyberspace. |
- Insider Threats: The Next Frontier for Security Resellers and SMBs
- Complete Security and Your Bottom Line: Sophos, Value and the Channel
- Tough Threats, Tougher Security: How You Can Leverage New Solutions To Combat A “Targeted Attack” Landscape
- Dark Clouds Ahead: Why the Mid-Market Needs To Ramp Up Cloud Security and How You Can Help Them Get There
