E-Mail:
Get our new Windows 7 eBook (PDF) for $7 with 70+ Tips. Download Now!

Vista Windows Mail Vulnerability Disclosed

  • No Related Post

Kingcope, a security researcher that has started an exploit selling service, has disclosed a new vulnerability in Windows Mail. Windows Mail is Windows Vista replacement for Outlook Express.

Symantec’s DeepSight network, which issued a warning about the vulnerability in Windows Mail early this morning, upped the threat rating from 6.8 to 7.5 in a follow-up alert after it confirmed that the bug was remote code exploitable. That means an attacker could introduce his or her own malware onto a compromised computer. Windows Mail is the successor to Outlook Express, the entry-level e-mail app that’s been bundled with the operating system since the Windows 95 edition.

By crafting an e-mail message with a link to a malicious file — one hosted on a remote Internet server, say — and duping the recipient to click on the link, an attacker could infect a Vista PC with software that steals identities or with a backdoor Trojan horse.

In some cases, all that’s required is that the user clicks on the link, said Symantec. “An attacker can deliver an e-mail message containing a malicious link that references a local executable,” the DeepSight alert read. “If the victim clicks on this link, the native program is executed with no further action required. For instance: An attacker could achieve the execution of the local file ‘winrm.cmd.’”

If run, “winrm.cmd” — the Windows Remote Management command-line tool — would give an attacker complete access to a PC.

Microsoft is down playing the potential risk but this is just another chink in armour. Vista’s security has hardly been fool proof and as more security vulnerabilities are found in the new OS, security experts are questioning reports that Microsoft’s new OS is the most secure system yet.

I said it before and I’ll be saying it again…reinstall XP, or if you are due for a new computer try to get one with XP, buy a Mac, or try Ubuntu .

[Exploit-for-sale hacker pins bug on Vista's e-mail app]

[tags]Microsoft, Microsoft Vista, Microsoft Windows Vista, Windows Vista, Vista[/tags]

2 Comments

What other vista hacks are there? (Besides the absurd speech one.) I mean proven not “for sale” some russian forum board. Also, the fact that IE 7 runs sandboxed alone makes it more secure than XP. The other suggestions are fine but to say you should go back to xp for security is laughable.

This is very interesting - I never knew Vista had a mail client. I have just tried Windows Mail and think the microsoft communities are good - just will stick with Outlook for email….

What Do You Think?

 

Posted Recently

Seagate 1.5 TB SATA Hard Drive for under $100 + Free Shipping!

Up to 40% off Logitech Harmony One Touch Screen Advanced Universal Remote + Free Shipping!

Motorola Droid A855 Phone for only $150 + Free Shipping!

Up to $200 off Data Robotics DroboPro 8-Bay USB 2.0/FireWire 800/iSCSI Storage Array

Up to $30 off Apple Mac mini with 2.53 GHz Core 2 Duo + 320 GB HD + 4 GB RAM + Free Shipping!

Nintendo Wii Console with Wii Fit Plus, $50 Gift Card for $290 + Free Shipping!

Logitech Performance Mouse MX for as low as $80.10 + Free Shipping!

Char-Broil The Big Easy Oil-Less Infrared Turkey Fryer for $140 + Free Shipping!

Logitech MX 1100 Cordless Laser Mouse for as low as $40 + Free Shipping!

Western Digital 2 TB Caviar Green SATA Hard Drive for $190 + Free Shipping!

Buy an LG Blu-ray Player, Get 3 Blu-ray Movies for Free!

Logitech Harmony 890 Universal Remote Control for $100 + Free Shipping!!

Seagate FreeAgent Go 250 GB Portable External Hard Drive for $60 + Free Shipping!

Up to 50% off TomTom GO 720 Portable GPS Navigator + Free Shipping!

Logitech Harmony 880 Advanced Universal Remote Control for $124 + Free Shipping!

Up to $100 Gift Card with Select ASUS Thin and Light Laptops

TomTom GO 730 Portable GPS Navigator for as low as $120 + Free Shipping!

Western Digital 1.5 TB Caviar Green SATA Desktop Hard Drive for $109 + Free Shipping!

Save up to 39% and get free shipping on Harmony 1100 Advanced Touch Screen Universal Remote Control

Panasonic Lumix DMC-ZS3 10MP Digital Camera for $285 + Free Shipping!

61 queries / 1.219 seconds.