Microsoft patching its cracks in Vista

  • Associated Press
  • Wednesday, February 14, 2007 9:00pm
  • Business

“Patch Tuesday,” when Microsoft Corp. releases repairs for problems in its software, came and went this week with six critical fixes – including the first one that touches Vista, the new operating system billed as the most secure Windows version yet.

The hole registers high on the irony scale: The flaw was in a “malware protection engine” that helps several Microsoft security products – including “Windows Defender” for Vista – guard against online threats. The problem could let an outsider “take complete control” of a victim’s computer, according to Microsoft’s security advisory.

This isn’t to say that Vista had previously appeared clean. Already a few vulnerabilities have popped up – including a remarkably low-tech hack.

In that case, security researchers noted a problem with Vista’s improved speech-recognition system, which lets people speak commands to the computer. It turns out that sounds played over the PC’s speakers – on a malicious Web site configured for this very purpose, for example – can trigger Vista’s speech-recognition engine and execute commands on a victim’s computer.

Mark Griesi, a security manager at Microsoft, acknowledged that the company was investigating the vulnerability, but said it was unaware of any attacks that exploited it.

There are many factors reducing the likelihood of such an attack. A victim would need to have activated speech-recognition – and have the PC’s microphone and speakers on. And if anything suspicious like “delete all data” were coming through, the user could just shut the sound off.

Still, some observers said Microsoft could have installed protections that would have prevented any problem.

That’s not what the company wants to hear as it touts – legitimately, in the eyes of many analysts – “fundamental architectural changes” in the name of computer security.

Joanna Rutkowska, a security researcher for COSEINC, a Singapore-based tech-services company, initially had high praise for Vista. But she said subsequent exploration revealed troubling weaknesses – even in features that are supposed to enhance Vista’s security.

After Rutkowska pointed out such issues, a Microsoft security manager wrote on his blog that Vista had intentionally made accommodations for user convenience and making sure applications worked properly – and that those decisions did not amount to “security bugs.”

Rutkowska replied that she now wondered whether Vista’s security model was “a big joke.” In an e-mail interview Wednesday, she wrote that she still believed Vista could successfully raise the security bar, “but only if Microsoft changes its attitude.”

“Even though there are some flaws in it currently … they could be fixed over time, if Microsoft put enough effort in doing this,” she wrote. Otherwise, “in a couple of months the security of Vista (from the typical malware’s point of view) will be equal to the security of current XP systems.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

The Verdant Health Commission holds a meeting on Oct. 22, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Verdant Health Commission to increase funding

Community Health organizations and food banks are funded by Swedish hospital rent.

Sound Sports Performance & Training owner Frederick Brooks inside his current location on Oct. 30, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood gym moves to the ground floor of Triton Court

Expansion doubles the space of Sound Sports and Training as owner Frederick Brooks looks to train more trainers.

The entrance to EvergreenHealth Monroe on Monday, April 1, 2019 in Monroe, Wash. (Andy Bronson / The Herald)
EvergreenHealth Monroe buys medical office building

The purchase is the first part of a hospital expansion.

The new T&T Supermarket set to open in November on Oct. 20, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
TT Supermarket sets Nov. 13 opening date in Lynnwood

The new store will be only the second in the U.S. for the Canadian-based supermarket and Asian grocery.

Judi Ramsey, owner of Artisans, inside her business on Sept. 22, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Artisans PNW allows public to buy works of 100 artists

Combo coffee, art gallery, bookshop aims to build business in Everett.

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Everett-based Helion receives approval to build fusion power plant

The plant is to be based in Chelan County and will power Microsoft data centers.

The Port of Everett’s new Director of Seaport Operations Tim Ryker on Oct. 14, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett names new chief of seaport operations

Tim Ryker replaced longtime Chief Operating Officer Carl Wollebek, who retired.

The Lynnwood City Council listens to a presentation on the development plan for the Lynnwood Event Center during a city council meeting on Oct. 13, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood City Council approves development of ‘The District’

The initial vision calls for a downtown hub offering a mix of retail, events, restaurants and residential options.

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Closure of Fred Meyer leads Everett to consider solutions for vacant retail properties

One proposal would penalize landlords who don’t rent to new tenants after a store closes.

Everly Finch, 7, looks inside an enclosure at the Reptile Zoo on Aug. 19, 2025 in Monroe, Washington. (Olivia Vanni / The Herald)
Monroe’s Reptile Zoo to stay open

Roadside zoo owner reverses decision to close after attendance surge.

Trade group bus tour makes two stops in Everett

The tour aimed to highlight the contributions of Washington manufacturers.

Downtown Everett lumberyard closes after 75 years

Downtown Everett lumber yard to close after 75 years.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.