Microsoft backports Windows 10 security measures to Windows 7 and 8.1

Microsoft has improved the security of Windows Vista, Windows 7, Windows 8(.1) and Windows RT by adding a security measure originally developed for Windows 10. The update that adds the measures is relatively unique according to a security researcher working for Google, James Forshaw. According to him it's uncommon that these kind of security measures are backported to older Windows versions.

symbolic-link

"Therefore I feel this is a good example of a vendor developing mitigations in response to increased attacks using certain techniques which wouldn't have traditionally been considered before for mitigations", Forshaw applaudes Microsoft.

Earlier this month Microsoft released an update for all Windows versions after Vista. The Redmond software giant wrote that the update, "addresses the vulnerabilities by correcting how Windows Object Manager handles object symbolic links created by a sandboxed process, by preventing improper interaction with the registry by sandboxed applications, and by preventing improper interaction with the filesystem by sandboxed applications."

Before the update, users with lower rights could create symbolic links in older Windows versions. Symbolic links aren't unsafe in itself but they can assist attackers to exploit other vulnerabilities. Microsoft warns they can assist in bypassing security measures and in elevation of privileges.

With the update Microsoft has added new security measures to make sure these can't be exploited anymore in Windows Vista, Windows 7, Windows 8(.1) and RT. In Windows 10 this security measure was already in place.

No posts to display