Microsoft Updates Malware Search Engine
- Author Koudstaal Monica
- Published May 14, 2011
- Word count 426
Microsoft launched Malware Protection Engine 1.1.6603.0, an updated version of its Microsoft Malware Protection Engine (MPE) application, on February 23, 2011. The updated MPE fixes a major security loophole (Elevation of privileges) that let attackers, who already gained access to a user's computer, to enhance their user permissions so as to obtain administrative rights on the computer. Once exploited the loophole, an attacker could shoot arbitrary code or commands from the system and capture it completely. Thereafter, an attacker could install programs or applications, edit, view, modify, or remove data from the computer with full administrative rights.
If not fixed, an attacker could exploit a locked-down Windows PC by entering in it and launching an attack script, which converts a registry key into a special value or code. When the MPE runs its subsequent scan, it runs the specially-crafted key that equals the attacker's privilege rights to the genuine user rights due to the fact that the preset LocalSystem rely on the computer. Generally, LocalSystem has major privileges and is used by the service control manager. For creating all this mess, the attacker needs to be on the computer with authentic login credentials because unknown users can not use this loophole.
All the applications or services in Windows XP and 2003 can be masqueraded despite the attributed privilege rights. The impersonation practice could be continued by an attacker irrespective of the inclusion of various latest security features designed to protect threads from such activity. The IT managers are advised to run processes/applications as regular users with must-have privileges on considering the likely occurrence of such practice of exploiting this security loophole. Therefore, they are not required to run SQL Server processes/applications as Local Service or Network Service. Further, computers running on Microsoft Internet Information Services are recommended not to run ASP.NET-based web applications in full-trust mode.
MPE is featured in a number of Microsoft security applications including Microsoft Security Essentials (MSE), Forefront Client Security, Windows Live OneCare, and Forefront Endpoint Protection 2010 among others. Given that these applications update themselves regularly, the administrators and users will receive the new update automatically in 48 week time or by the end of the weekend, as per the company.
Though, Microsoft has not come upon any malpractices preying on the security loophole, the chances of threat occurrence were good enough for the company to update its application. The Elevation of privileges threat was founded by the Cesar Cerrudo, the CEO of Argeniss, a security research firm. Cesar Cerrudo publicly issued his 'Token Kidnapping' research during the Black Hat security conference in July 2010.
Just a phone call away You can reach V tech-squad online technical support at their Toll Free No +1-877-452-9201 For US/CA. V tech-squad Inc. is a leading provider of online computer support, virus removal, home networking support, phone support, and ipad support. V tech-squad has a team of certified technicians who cumulatively have more than 100 years of experience in desktop support.
Article source: https://articlebiz.comRate article
Article comments
There are no posted comments.
Related articles
- Roots of Renewal: How Organic Gardening Restores the Earth and Nourishes Homegrown Abundance.
- Maximalist Holiday Magic: Embroidered Window Toppers, Jewel Tones & Vintage Doors
- Embrace Holistic Well-Being with Thoughtful Yoga & Meditation Essentials
- Effortless Holiday Resort Style: Boho Skirts and Handmade Treasures
- Cyber Monday Lash Shopping Guide: Build a Complete Holiday Eye Look with Soft Magnetic Lashes
- The Ultimate Black Friday Guide to Soft Magnetic Lashes
- Why Recurring Income Streams Are the Smartest Way to Build Real Wealth in 2025 and Beyond.
- Woodsy Retreat with Rustic Modern Farmhouse Carved Doors
- How To Train Your Staff For A Successful Fire Safety Inspection (A Guide For British Businesses)
- The Simple Changes Every Driver Can Make To Reduce Their Carbon Footprint
- From Obscurity To Spotlight: Elevating 5 Underappreciated Instruments In Modern Music
- Proven Strategies for Earning Serious Money Through Digital Products in 2025.
- Unlocking Wealth in the World's Largest Marketplace: Why Amazon Remains the Ultimate Money-Making Machine in 2025.
- Tracing Roots in the Digital Age: How Modern Genealogy is Revolutionizing Family History Research.
- Unlocking Primal Vitality: How the Paleo Diet Can Transform Your Health and Energy in the Modern World.
- New Shipment From India! Nature’s Harmony Carved Doors + Free Shipping Black Friday Deal
- New Arrivals: Artisan-Crafted Heritage Revival Furniture Collection
- How to Realistically Earn $1,000 a Day Online: The Path That Thousands Have Already Walked.
- Carb Cycling for Weight Loss: The Science-Backed Strategy That Keeps Metabolism Revved and Fat Burning High.
- Why You Should Look After Your Pets: The Lifelong Rewards of Responsible Care for Cats and Dogs.
- Etsy in 2025: Navigating Trends, Growth, and Opportunities in the Handmade Marketplace.
- Unlocking Profits: How Anyone Can Make Money with ChatGPT in 2025.
- Cultivating Nature’s Bounty: The Comprehensive Guide to Organic Gardening Success.
- The Science, Myths, and Strategies for Healthy Longevity
- Build Strength, Endurance, and Longevity.
- Email Marketing: The Timeless Strategy Driving 40x ROI in 2025.
- The Keto Revolution: Unlocking Peak Health Through Low-Carb Mastery.
- Intermittent Fasting: The Complete Guide to Transforming Your Health, Energy, and Longevity.
- Making Money With Facebook Ads.
- Clickbank Affiliate Marketing: The Ultimate Guide to Earning Passive Income in 2025.