ASE Labs
Welcome Guest. Please register or log in now. There are 8 people online (0 Friends).
  • Home
  • Articles
  • News
  • Forum
  • Register/Login

Qihoo 360 Detects Oldest Vulnerability in Microsoft OS

Poster: SySAdmin
Posted on November 25, 2010 at 8:07:01 AM
Qihoo 360 Detects Oldest Vulnerability in Microsoft OS

BEIJING, Nov. 25, 2010 /PRNewswire-Asia/ -- Today, China's leading network security services provider, Qihoo 360, released an emergency network security warning, claiming that it has first discovered an Exploit Code of an 18-year latent high-risk 0day vulnerability that affects all Windows versions. This vulnerability named as "elder" is very likely to confront worldwide computer users with a new round of malicious attacks. However, netizens on the Chinese Mainland do not need to worry about that. 360 Safe, the flagship security software of Qihoo 360, is upgrading the temporary kernel security patches and can perfectly immunize against the security problems caused by this vulnerability. 

According to Dr. Shi Xiaohong, a security expert of Qihoo 360: "Since 1992, there has been a local privilege escalation vulnerability in the Windows operating system, through which hackers may seize the highest control of the system and easily undermine or prohibit any security software, including anti-virus software, firewall, proactive defense software, sand box and the system restore. They can also hack around the UAC protection of Windows Vista/Win7 or elevate the privilege on a server website to take control of the vulnerability network server, and directly threaten the information security of government, enterprises, Internet bars and PC users.

"This 18-year latent high-risk 0day vulnerability will affect all Windows operating system versions including Windows NT4.0, Windows 2000, Windows XP, Windows 2003, Windows Vista, Windows 7, Windows Server 2008, etc.," said Dr. Shi Xiaohong, who also claimed that the researchers in Qihoo 360 independently discovered this vulnerability at the end of October this year, and informed MSRC of the details of the vulnerability and demonstration program and assisted Microsoft to make the security patch for the vulnerability so as to solve this security problem, while Microsoft also acknowledged it was a serious privilege escalation vulnerability.

"If you liken Trojan horses to thieves sneaking into homes, then the local privilege escalation vulnerability may turn this thief into the host of your homes and do whatever it wants to do, since they can directly shut up or bypass any antitheft device you have installed. Qihoo 360's security experts suggested that previously Stuxnet has just used another Windows local privilege escalation vulnerability (CVE-2010-2743) to seize control of the system. This vulnerability first appeared in 1995 and has a latency of 15 years. In addition, in January 2010, Google's engineers also revealed an 'elder' vulnerability that existed since 1993. However, this time Qihoo 360 has discovered the "the oldest 0day vulnerability in history".

Qihoo 360 has been the first to intercept high-risk 0Day vulnerability attacks many times in China, including the vulnerabilities in IE XML, Microsoft Mpeg-2 video and Office web part, and also has received the public thanks of Microsoft for being the first to discover vulnerability in the Directshow video development Kit. The only domestic company for China's personal computer security, Qihoo 360, as the first company to independently discover this "18-year-ole 0day" vulnerability, again refreshes the records of China's security industry.

Dr. Shi Xiaohong said, "In the next 48 hours, all 360 Safe users just need to open 360 Trojan firewall with Internet connection. The 360 Safe will automatically update the temporary kernel patches directed against the vulnerability. Without any other operation, you can arm your computers with the exact immunities. Before Microsoft launches its official patch for the vulnerability, in order to protect users from the harm of this vulnerability, 360 Security Center will not disclose any technical details of the vulnerability temporarily," revealed Shi Xiaohong.

About Qihoo 360

Founded in July 2006, Qihoo 360 is the leading Internet security services provider in China. Our goal is to secure the Internet and destroy the cyber criminal ecosystem. With innovative cloud security technology and the world's largest cloud security system, Qihoo 360 discovers and defends from more than 3 millions new Trojans, plug-ins, and malwares every day, and cleans up hundreds of millions of intrusion or infection incidents. Qihoo 360 offers full-fledged, totally free-of-charge security products, such as 360 Safe, 360 Antivirus, 360 Secure Browser, 360 Safe Box, 360 Software Manager, and 360 Mobile Safe; protects Internet and mobile users; and ensures their security while online or on-the-go.

SOURCE  Qihoo 360 Technologies Co. Ltd.

Qihoo 360 Technologies Co. Ltd.

CONTACT: Yin Xiaoshan, 360 Security Center at +86-10-5878-1377 or yinxiaoshan@360.cn
 
Print This Entry
Tags PR Press Release
Related Articles
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
Login
Welcome Guest. Please register or log in now.
Forgot your password?
Navigation
  • Home
  • Articles
  • News
  • Register/Login
  • Shopping
  • ASE Forums
  • Anime Threads
  • HardwareLogic
  • ASE Adnet
Latest News
  • Kingston HyperX Cloud 2 Pro Gaming Headset Unboxing
  • Synology DS415+ Unboxing
  • D-Link DCS-5020L Wireless IP Pan/Tilt IP Camera
  • Actiontec WiFi Powerline Network Extender Kit Unboxing
  • Durovis Dive Unboxing
  • Bass Egg Verb Unboxing
  • Welcome to the new server
  • Gmail Gets Optional Preview Pane
  • HBO Go on Consoles
  • HP Touchpad Update
Latest Articles
  • D-Link Exo AC2600 Smart Mesh Wi-Fi Router DIR-2660-US
  • HyperX Double Shot PBT Keys
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones
  • ScharkSpark Beginner Drones
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera
  • Contour Unimouse Wireless Ergonomic Mouse
  • HyperX Cloud Alpha Pro Gaming Headset
  • Linksys Wemo Smart Home Suite
  • Fully Jarvis Adjustable Standing Desk
Latest Topics
  • Hello
  • Welcome to the new server at ASE Labs
  • Evercool Royal NP-901 Notebook Cooler at ASE Labs
  • HyperX Double Shot PBT Keys at ASE Labs
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones at ASE Labs
  • ScharkSpark Beginner Drones at ASE Labs
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard at ASE Labs
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera at ASE Labs
  • Kingston SDX10V/128GB SDXC Memory at ASE Labs
  • What are you listening to now?
  • Antec Six Hundred v2 Gaming Case at HardwareLogic
  • Sans Digital TR5UTP 5-Bay RAID Tower at HardwareLogic
  • Crucial Ballistix Smart Tracer 6GB PC3-12800 BL3KIT25664ST1608OB at HardwareLogic
  • Cooler Master Storm Enforcer Mid-Tower Gaming Case at HardwareLogic
  • Arctic M571-L Gaming Laser Mouse at ASE Labs
  • Contour Unimouse Wireless Ergonomic Mouse at ASE Labs
Advertisement
Advertisement
Press Release
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • Fujifilm launches "instax SQUARE SQ6 Taylor Swift Edition", designed by instax global partner Taylor Swift
  • Huawei nova 3 With Best-in-class AI Capabilities Goes on Sale Today
  • Rand McNally Introduces Its Most Advanced Dashboard Camera
  • =?UTF-8?Q?My_Size_to_Showcase_Its_MySizeId=E2=84=A2_Mobil?= =?UTF-8?Q?e_Measurement_Technology_at_CurvyCon_NYC?=
Home - ASE Publishing - About Us
© 2010 Aron Schatz (ASE Publishing) [Queries: 16 (8 Cached)] [Rows: 292 Fetched: 35] [Page Generation time: 0.011895895004272]