Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Guru3D Rig of the Month - February 2021
ASUS GeForce RTX 3060 STRIX Gaming OC review
EVGA GeForce RTX 3060 XC Gaming review
MSI GeForce RTX 3060 Gaming X TRIO review
PALIT GeForce RTX 3060 DUAL OC review
ZOTAC GeForce RTX 3060 AMP WHITE review
Fractal Design Meshify 2 Compact chassis review
Sabrent Rocket 4 PLUS 2TB NVMe SSD review
MSI Radeon RX 6900 XT GAMING X TRIO review
Guru3D Q1 Winter 20/21 PC Buyer Guide

New Downloads
Display Driver Uninstaller Download version 18.0.3.7
Guru3D RTSS Rivatuner Statistics Server Download 7.3.0 Final
Media Player Classic - Home Cinema v1.9.10 Download
GeForce 461.72 WHQL driver download
AIDA64 Download Version 6.32.5640 beta
CrystalDiskInfo 8.11.2 Download
AMD Radeon Adrenalin Edition 21.2.3 driver download
GPU-Z Download v2.37.0
Intel HD graphics Driver Download Version: DCH27.20.100.9313
HWiNFO Download v6.43 - 4380 Beta


New Forum Topics
Intel Core i7-11700K Rocket Lake-S is already selling at German etailer Who needs a 3080 if you can get GeForce Now.. Afterburner's Sytem Tray icons font options RTSS 6.7.0 beta 1 Next-gen AMD EPYC (Genoa) Would get 50% larger socket SP5, 96 cores and 400W TDP Radeon RX 6700 XT would have a starting price of 479 USD and see better availability Just did raid 0 m2 ssds GeForce RTX 3090 with blower style coolers discontinued en masse MSI Z490 Motherboards Open Up for PCIe 4.0 Graphics Cards and SSDs AMD Radeon Software Adrenalin 2020 Edition 21.2.3




Guru3D.com » News » Microsoft releases emergency patch for Windows 7

Microsoft releases emergency patch for Windows 7

by Hilbert Hagedoorn on: 04/02/2018 07:52 AM | source: | 15 comment(s)
Microsoft releases emergency patch for Windows 7

Microsoft released an out of band emergency patch for a vulnerability in Windows 7 and Windows Server 2008. This was necessary after a security researcher discovered that a Meltdown-patch released in January this year, introduced a new and even bigger vulnerability.

The patch released in January should have protected Windows 7 and Windows Server 2008 systems against the Meltdown attack writes myce. Unfortunately the update introduced a new vulnerability that allowed any random process to read the entire system’s memory and to write data to it. Security researchers Ulf Frisk discovered the new issue and according to him the vulnerability is fairly easy to exploit.

Microsoft reports the vulnerability allowed a logged in attacker to use a specially crafted application to take control of an affected system. “An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights,” Microsoft further explains.

Therefore, Microsoft decided to release an emergency patch outside its regular Patch Tuesday release-cycle. The software giant strongly advises users to install the update as soon as possible. Microsoft hasn’t discovered any attacks exploiting the vulnerability in the wild yet, but the company expects that’s only a matter of time.







« Radeon Vega20 Gets Spotted in Linux AMDGPU driver · Microsoft releases emergency patch for Windows 7 · Shuttle Introduces DL10J, Fanless Gemini Lake PC »

Related Stories

Microsoft will Increase Windows license fees for high-end hardware - 03/30/2018 07:12 AM
It has been mentioned before, different Windows 10 licensing models based on the hardware you use. Currently, there is wordout on the street that Microsoft plans to raise license fees for computers wi...

Microsoft DirectX Raytracing - EA Real-time Raytracing Experiment - 03/20/2018 08:12 AM
EA also shared a video demoing Real-time Raytracing. PICA PICA' is a demo and experiment using SEED's 'Halcyon' research engine and Microsoft's new DirectX Raytracing API to do real-time GPU ray...

Microsoft announces DirectX Raytracing for real-time raytracing - 03/20/2018 07:46 AM
Shortly after the Nvidia announcement, Microsoft follows by adding DirectX Raytracing to the DirectX 12 api. According to the manufacturer, the technology clears the way for games that are partly buil...

Microsoft DirectX Raytracing - Remedy Example Video - 03/20/2018 07:46 AM
Remedy Entertainment discussed the experiments and research we have done in collaboration with Nvidia on the Microsoft DirectX Raytracing (DXR) API that enables straightforward access to real-time ray...

Intel and Microsoft release final Spectre Patches up to and including Sandy Bridge - 03/15/2018 03:24 PM
As Intel finalizes them, Microsoft started distributing Microcode updates for the Spectre variant 2, the updates now have a reach from the latest Coffee Lake processors, Kaby Lake (Core iX-7xxx and iX...


3 pages 1 2 3


Fox2232
Senior Member



Posts: 11503
Joined: 2012-07-20

#5534115 Posted on: 04/02/2018 08:08 AM
And they forgot to mention that attacker may as well flash BIOS (unless flash protected form OS), to have full list of "popular" exploits these days...
...as it seems that flashing BIOS is most important thing attacker wants to do once he has control over system.

Picolete
Senior Member



Posts: 320
Joined: 2014-12-09

#5534132 Posted on: 04/02/2018 10:38 AM
If I secure my BIOS with a password, shouldn't i be secure from some of this exploits?

Fox2232
Senior Member



Posts: 11503
Joined: 2012-07-20

#5534136 Posted on: 04/02/2018 11:11 AM
If I secure my BIOS with a password, shouldn't i be secure from some of this exploits?

It was a joke from my side. Writing code which works at boot time and still allows normal system operation is not that easy in limited space of BIOS flash. So it is one of last targets attacker has on list. (If it even gets to list as each MB requires different BIOS and has different kinks which may prevent system from being operational and therefore lost even to attacker himself.)

Meltdown/spectre and similar are not spawning from BIOS therefore password on BIOS does not protect against them. (OS level attacks.)
But in case they allow attacker to gain control over your system, you do not need BIOS-Admin-Password. You need settings preventing BIOS flashing from OS.

Rich_Guy
Senior Member



Posts: 12622
Joined: 2003-05-11

#5534159 Posted on: 04/02/2018 01:00 PM
Link to the patch in the catalog ?

vonSternberg
Senior Member



Posts: 151
Joined: 2017-09-12

#5534160 Posted on: 04/02/2018 01:03 PM
Has anyone even been affected by it? I haven't updated my Windows 7 since 2012 and have never had any issues.

3 pages 1 2 3


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2021