Id Theft Protect
Home Identity Fraud Statistics Learn More About ID Theft FAQ About Us Contact Us
Sign In
Register
24th May 2013
05.01.2012 How to block web browser scripts
IDENTITY THEFT and IDENTITY FRAUD News a...
05.01.2012 New online bank fraud identified
IDENTITY THEFT and IDENTITY FRAUD News a...
05.01.2012 WordPress 3.3 XSS flaw patched
IDENTITY THEFT and IDENTITY FRAUD News a...
More   More News
Identity Fraud Statistics
One in six of all broadband customers surveyed left their Wireless router unprotected and one in nine - that's more than 3.5 million customers said that they did piggyback on someone's else Wireless connection.
(moneysupermarket.com, September 2008)
spacer
US women were 26 percent more likely to be fraud victims than US men.
(Wells Fargo/Intersections Inc, February 2009)
More  
Search ID Theft Protect
go
ID THEFT PROTECT - News and Views 24/05/2013
Windows UAC malware threat
26.11.2010

IDENTITY THEFT and IDENTITY FRAUD News and views - This daily news service searches the web to bring you relevant news to your desktop


A new zero-day attack against Windows, capable of bypassing the User Access Control (UAC) protections introduced in Windows Vista and designed to prevent malware from gaining administrative access without user authorisation, has been discovered in the wild.

The proof-of-concept implementation of the infection technique, known as Troj/EUDPoC-A, was posted to a Chinese educational forum before being discovered by anti-virus researchers from various security firms.Chester Weisniewski, of anti-virus vendor Sophos, warns that the technique used by the Trojan 'enables an attacker to impersonate the system account, which has nearly unlimited access to all components of the Windows system,' and does so without triggering the User Access Control protections introduced by Microsoft to prevent exactly that occurring.

The flaw targeted by the code is thought to exist in all versions of Windows from Windows XP onwards - including Windows 2008 R2 and fully-patched Windows 7 systems, and thus far no fix for the issue is available from Microsoft.

Marco Giuliani of security firm PrevX warns that the proof of concept code 'could potentially become a nightmare' as ne'er-do-wells rush to take advantage of the flaw before it is patched by Microsoft. 'We expect to see this exploit being actively used by malware very soon,' Giuliani explained, 'it's an opportunity that malware writers surely won't miss.'

The vulnerability is thought to be under active investigation by Microsoft, but so far there has been no word as to an estimated release date for a fix. In the meantime, Sophos has a workaround for the flaw, but it is unlikely to offer much protection against maliciously modified variants.

Source: ID Theft Protect News Feed

Search Related News: microsoft, windows, security, patch, zero day

Join our Twitter feed!

avast! Free Antivirus

Search more news

Our Promotions - Be safe when shopping in 2012!