Microsoft has issued a security advisory, and encouraged users of Windows Vista and Windows 7 to disable the Windows Sidebar and associated gadgets. The move comes just before a scheduled talk at BlackHat this month, where researchers will explore the types of flaws that exist in existing gadgets, as well as other weaknesses.
Microsoft’s advisory provides a FixIt tool, which will disable the Windows Sidebar and any gadget that is currently enabled on the system. The measure is necessary, Redmond said, because it will protect customers from “…vulnerabilities that involve the execution of arbitrary code by the Windows Sidebar when running insecure Gadgets.”
“In addition, Gadgets installed from untrusted sources can harm your computer and can access your computer’s files, show you objectionable content, or change their behavior at any time.”
As mentioned, Microsoft is likely reacting to a talk scheduled for BlackHat titled, We Have You By The Gadgets. Presented by researchers Mickey Shkatov and Toby Kohlenberg, the talk will delve into their work on “creating malicious gadgets, misappropriating legitimate gadgets, and the sorts of flaws we have found in published gadgets.”
This could be problematic for Vista and Windows 7 users who happen to have left their systems as they were the day they came out of the box – almost all of which have the gadgets enabled.
“Clearly Microsoft is worried about the security researchers’ findings…Microsoft hasn’t issued a security patch to fix the vulnerability. They’re suggesting you completely nuke your Windows Sidebar and Gadgets,” commented Sophos’ Graham Cluley.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Chrome 114 Released With 18 Security Fixes
- Organizations Warned of Backdoor Feature in Hundreds of Gigabyte Motherboards
- Breaking Enterprise Silos and Improving Protection
- Spyware Found in Google Play Apps With Over 420 Million Downloads
- Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability
- Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery
- PyPI Enforcing 2FA for All Project Maintainers to Boost Security
- Personal Information of 9 Million Individuals Stolen in MCNA Ransomware Attack
