Security vendor circumvents Windows Vista's Patchguard

Microsoft vows to block shortcut

Written by Tom Sanders in California

Security researchers with Authentium have found a way to circumvent the Patchguard security technology that Microsoft has built into the 64-bit version of its forthcoming Windows Vista operating system.

Over the past months the Patchguard technology has been subject of a fierce debate between security vendors and Microsoft because it prevents some anti-virus software from functioning.

Facing potential penalties from antitrust authorities in Korea and the EU, Microsoft earlier this month promised to provide application programming interfaces (APIs) that would allow third party security products to function properly in Windows Vista. It may take years however before these APIs will be published and fully functioning.

Authentium's technology allows an application to effectively disable Patchguard. The company decided to develop the tool because it required kernel access for its VirtualATM product that is scheduled for release in December.

In a blog posting the company argued that providing kernel access to third party websites will enable future security innovations.

"This is about enabling innovative new technologies and countering new emerging threats and criminal strategies. If new security innovations are not encouraged, consumers will lose out."

"If we (the good guys) can gain access to the Vista kernel, so can sophisticated, well-financed hackers. These days, most hackers are exactly that – sophisticated and well-financed. We implore Microsoft not to 'go it alone' in security."

Microsoft however said that it will not tolerate outside developers circumventing its technology features and plans to issue a patch to block Authentium's technique.

"If a vulnerability is discovered in Kernel Patch Protection, Microsoft will issue a security update as part of the standard Microsoft Security Response Center process," the company said in an emailed statement.

"Microsoft strongly recommends that software vendors do not attempt to bypass Kernel Patch Protection. This has the potential of destabilising and crashing customer systems, particularly in cases where Kernel Patch Protection is enhanced and updates are delivered to customers."

Microsoft stressed that it will provide APIs to offer functionality similar to that which developers had in other Windows versions.

Tags:

Further reading

Related articles

China accused of Trojan onslaught

Trail leads back to China-based operations including a government website   More...

Hackers turn to drive-by downloads

Organised crime exploiting browser vulnerabilities   More...

TechEd 2007: Security should be taught in schools

More user education and better collaboration needed to beat online threats   More...

Antivirus struggles on 64-bit Vista

35 per cent of 64-bit Vitsa antivirus software receives failing grade   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement