Microsoft patches security bugs in Vista gadgets
By Ruben Francia
Microsoft has released a security patch for Windows Vista to resolve the vulnerabilities on its small desktop applications, Vista Gadgets, which could allow an anonymous remote attacker to run code with the privileges of the logged on user.
The vulnerabilities are found in Feed Headlines gadget, Contacts gadget and Weather gadget.
According to Secunia, successful exploitation requires that a user is tricked into subscribing to a malicious RSS feed in the Feed Headlines gadget using Internet Explorer or into adding/importing a malicious contact into the Contacts gadget. For Weather gadget, successful exploitation requires a Man-in-the-Middle attack.
In addition, Microsoft said that “in all attack vectors, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.â€
Microsoft has recommended that users apply the security update. The patch can be downloaded in both 32-bit and 64-bit versions of Vista.
Related:







August 14th, 2007
[…] Contact the Webmaster Link to Article windows vista Microsoft patches security bugs in Vista gadgets » Posted at […]
October 21st, 2007
hello - to this gadgets topic i just wanted to add my comment, like I have made a new site http://www.gadgetsdownload.com where you are welcome to upload your gadgets/widgets.