ilev Posted March 17, 2010 Share Posted March 17, 2010 An exploit writer at Core Security Technologies has discovered a serious vulnerability that exposes users of Microsoft?s Virtual PC virtualization software to malicious hacker attacks. The vulnerability, which is unpatched, essentially allows an attacker to bypass several major security mitigations -- Data Execution Prevention (DEP), Safe Exception Handlers (SafeSEH) and Address Space Layout Randomization (ASLR) -- to exploit the Windows operating system. As a result, some applications with bugs that are not exploitable when running in a not-virtualized operating system are rendered exploitable if running within a guest OS in Virtual PC, according to Ivan Arce, chief technology officer at Core. http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug -Vivicidal- 1 Share Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/ Share on other sites More sharing options...
itzwolf Posted March 17, 2010 Share Posted March 17, 2010 Not good at all... Will it be fixed is the question and how long till it is fixed. Is VPC even maintained anymore? Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/#findComment-592360724 Share on other sites More sharing options...
hdood Posted March 17, 2010 Share Posted March 17, 2010 Not good at all... Will it be fixed is the question and how long till it is fixed. Is VPC even maintained anymore? Yes. Probably a few weeks. Yes. Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/#findComment-592360732 Share on other sites More sharing options...
ilev Posted March 17, 2010 Author Share Posted March 17, 2010 Yes. Probably a few weeks. Yes. Microsoft knows about it for 7 months now. It may take another 7 months to fix. Meantime : don't use Virtual PC (like xp mode in Win7 ) "We recommend affected users to run all mission critical Windows applications on non-virtualized systems" or, use a Linux VM Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/#findComment-592360778 Share on other sites More sharing options...
hdood Posted March 17, 2010 Share Posted March 17, 2010 Microsoft knows about it for 7 months now. It may take another 7 months to fix. Well then. I guess I meant to say 2014. Meantime : don't use Virtual PC (like xp mode in Win7 ) "We recommend affected users to run all mission critical Windows applications on non-virtualized systems" or, use a Linux VM Good advice for everyone. Apart from the somewhat better integration with the host, VMWare Player and VirtualBox are much better than VPC. They're also free. Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/#findComment-592360806 Share on other sites More sharing options...
-Vivicidal- Posted March 17, 2010 Share Posted March 17, 2010 That vulnerability is just scary! I am interested by how the bug even works. Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/#findComment-592360808 Share on other sites More sharing options...
itzwolf Posted March 17, 2010 Share Posted March 17, 2010 Good advice for everyone. Apart from the somewhat better integration with the host, VMWare Player and VirtualBox are much better than VPC. They're also free. I use VirtualBox and haven't had any issues with it. (Y) Link to comment https://www.neowin.net/forum/topic/884384-virtual-pc-flaw-lets-hackers-bypass-dep-safeseh-aslr/#findComment-592361218 Share on other sites More sharing options...
Recommended Posts