• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Windows 7: Can an update make the system more vulnerable?

Windows 7: Can an update make the system more vulnerable?

29/03/2018 19:57 by giorgos

Microsoft Updates to Meltdown (CVE-2017-5754) appears to have accidentally exposed users using Windows 7 64-bit systems. These systems are reported to be susceptible much more than they were before the update, according to a researcher.

Let's remind that Meltdown is a hardware vulnerability that proved almost simultaneously by several groups of researchers.

broken glass - Windows 7: can an update make the system more vulnerable?

The vulnerability allows an attacker to access the contents of kernel memory in passwords and encryption keys, that is, from a part used by routine applications.

So Microsoft and many other companies tried to fix the vulnerability by updating operating systems (except for BIOS updates from manufacturers). So we saw two different updates for Windows in January and February.

But according to Ulf Frisk, something went wrong right from the first update released in January when it was installed on Windows 7 and Windows Server 2008 R2 systems. The update has omitted certain control permissions for something called Page Map Level 4 (PML4).

What is this;

It is a table used by Intel microprocessors to translate the virtual addresses of a process into physical memory addresses in RAM.

However, only the kernel must have access to this table. Because if things do not happen, they are very simple for every attacker.

It will not need smart exploits, since Windows 7 does all the hard work of mapping the required memory in every current process. The exploit is just a matter of reading and writing to an already paired virtual memory in operation. No complicated APIs or syscalls are required.

According to Frisk, the update was released on March Microsoft has fixed the problem on Windows 10, 8, and 7 32bit. This means that Windows 7 x64 systems that receive only the January and / or February updates are still affected.

Seeing systems more vulnerable (than before) after a security update is something we do not often see.

First there was an update on the flaw, which created a new and distinct defect, which required a new solution for repair.

But to be fair, Microsoft may have written the buggy code, but it was trying to cover completely security flaws that originated in the way hardware was designed two decades ago.

Following the above, we must once again emphasize the importance of immediately implementing any new updates.
OK with Microsoft good will be to wait a few days, especially in production systems.

 

  • Google Maps updated application with a Macedonian. Shake
  • Microsoft Office 2016 from the company's servers
Windows 7: Can an update make the system more vulnerable? was last modified: 29 March, 2018, 8: 09 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: exploits, I'm sure, kernel, memory, passwords, windows, Windows 7

You May Also Like

Netrunner 21.01 XOXO Dedian with the latest LTS kernel
What does Ctrl + Z do? More than you think
Troubleshoot oobekeyboard and BIOS problems

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Router Private and Public IP: What's On Your Router?
Next Post: Bitdefender: won 6 awards from AV TEST »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.