Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
Your Code in the Crosshairs

By Thomas Caywood

Excerpt:

"Barely a week after Windows Vista shipped in late January amid a flurry of hype about its rugged new security features, engineers at the penetration testing vendor Core Security Technologies successfully hijacked a Vista system by overflowing a buffer in CA's BrightStor ARCserve backup application …

"The same group uncovered a similar vulnerability in the ubiquitous Adobe Acrobat Reader helper applet that permitted attackers to execute malicious code under Vista. Patches are available for both the Acrobat and BrightStor vulnerabilities, but the incidents underscore the fact that Vista's newfound defenses can't protect systems against flawed or vulnerable code in third-party or homegrown applications …

"Core Security founder and CTO Ivan Arce says his firm proved the point in the lab with its successful Vista hack, which should serve as a wake-up call for developers."

Source: Redmond Developer News

View the full article

Related Content