Most Popular Stories
Events
- CTO Telecom Summit – May 31-Jun 3, 2009
May 31 - June 3, 2009 — Scottsdale, AZ - Four Seasons
Sponsored Links
Free Newsletter
Latest News
Popular Topics
Whitepapers
- The ECM Paradox: Extending Local Flexibility to Strengthen Central Control
- HIPAA Security Provisions
- The One Essential Guide to i5/OS and AIX Disaster Recovery
- Why Traditional Monitoring Tools Cannot Deliver True Mobile User Management for the BlackBerry Platform
- Gartner Magic Quadrant for Content Monitoring and Filtering and Data Loss Prevention
- Legal Applications of A2iA DocumentReaderâ„¢: Automated intelligent document classification, data extraction and search tools
Vista exploit: Annoying MySpace pages a threat?
It's only been a day since the first Vista patches were released and two days since the operating system was made available to the public. You know what that means: time for a vulnerability. ZDnet's George Ou reports that Vista's Speech Command feature leaves the OS open to malicious attack by--get this--sound files played back from a website that send commands to the OS. "I recorded a sound file that would engage speech command on Vista, then engaged the start button, and then I asked for the command prompt. When I played back the sound file with the speakers turned up loud, it actually engaged the speech command system and fired up the start menu," Ou wrote. "I had to try a few more times to get the audio recording quality high enough to get the exact commands I wanted but the shocking thing is that it worked! Anyone that's ever visited MySpace knows how many annoying webpages out there that will start blasting loud MP3 music as soon as they enter the page." The obvious workaround here is to disable Speech Command on user's machines. It remains to be seen, however, whether annoying MP3s of Panic! At the Disco can induce a kernel panic.
For more on the strange exploit:
- see Ou's blog entry at ZDnet
Related Article:
December Vista sales strong. Report
Related Stories
- Hackers respond to Patch Tuesday with exploits
- Zero-day bugs remain after Microsoft Patch Tuesday
- Windows XP SP3 in testing, coming in early 2008
- Hackers exploiting unpatched Windows DNS bug
- Patch Tuesday: Critical Vista, IE7 patches released
- Microsoft to offer tool for isolating zero-day exploits
- New Microsoft Word zero-day attack on the loose
- Symantec: Vista vulnerable to legacy exploits
- Windows flaw gets critical, patch coming tomorrow
- Firefox 2/IE 7 animated cursor exploit on the way
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





