Vista vulnerable to malware from 2004

Microsoft's Vista may be vulnerable to at least three pieces of widespread malware, two of which date back to 2004 , according to security vendor Sophos.

At least three well-known Internet worms -- labelled Stratio-Zip, Netsky-D and MyDoom-O by Sophos -- are able to execute on the OS, according Sophos.

These worms comprise 39.7 percent of all malware currently in circulation, according to the security vendor. The MyDoom and Netsky variants were first detected back in 2004.

Systems running Vista are vulnerable to the malware when running third-party e-mail clients, according to Sophos. Windows Mail Client -- the Vista replacement to Outlook -- will block the worms, but businesses running third-party e-mail clients such as Lotus Notes, or that permit Web-based mail such as Yahoo or Gmail, could be vulnerable.

Sophos decided to test Vista for resistance to common strains of malware after Microsoft co-president Jim Allchin made a comment that he would be happy for his seven-year-old son to use a locked-down version without antivirus.

"The comment about his seven-year-old spurred our idea -- let's see if malware runs on Vista," said Carole Theriault, senior security consultant at Sophos. "It does."

"I'm certainly not going to run Vista without antivirus," Theriault added. "And I wouldn't take the risk with my business. Who knows how many more pieces of malware run on it?"

Windows Mail Client will block these mass-mailers, as it detects double extensions. Some mass mailers try to hide their executable payloads behind another extension -- for example a text file. Mail Client will notice both the executable and the text file, and prevent the executable from running, in its default setting. However, Mail Client security features do not apply to third-party e-mail clients, which may not block malware adequately.

Although Sophos is recommending that businesses running XP eventually shift to Vista, as XP is less secure, Theriault said that for the time being businesses considering running Vista will still need to take security precautions.

"Vista is excellent, but it hasn't really changed the security landscape," said Theriault. "You still need antivirus, firewalls and patches at least."

Theriault said it was too early to predict the speed and scale of Vista uptake.

"People will listen to what's going on, and make a decision depending on what suits their environment best. It's too early to say," said Theriault.

These are among the first flaws found in the finalised version of Vista. The Vista kernel was hacked by a Polish security researcher at the Black Hat security conference this year, using virtualisation technologies. Security company Symantec also reported flaws in the Vista kernel in August.

Microsoft was approached for comment on this story but no spokesperson was available.

Tom Espiner of ZDNet UK reported from London.

Advertisement

Talkback 1 comments

  1. Correction Anonymous -- 03/12/06

    I'd like to submit this to the author/editor but I can't be bothered to find out how, and it's a small point anyway.

    I support both Outlook Express and Office Outlook and have trained in Windows Mail and Office 2007.

    Windows Mail is the replacement for Outlook Express, not Outlook. Outlook will continue on with Office 2007.

    It's just slightly misleading is all.


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured