Maltese researchers find elusive Windows bug

Maltese researchers had found an elusive 10-year-old Windows bug that can cause PC systems to crash. Dan Kaplan, writing in SCMagazineUS.com, quotes Paul Gafa, CTO of 2X Software, as saying that the denial-of-service condition can result if a user is...

Maltese researchers had found an elusive 10-year-old Windows bug that can cause PC systems to crash.

Dan Kaplan, writing in SCMagazineUS.com, quotes Paul Gafa, CTO of 2X Software, as saying that the denial-of-service condition can result if a user is tricked into running an application that contains the malicious code.

"You can be the least privileged user on the system and still crash it," he said. "I believe it is very easy for Microsoft to sort it out. They just need to validate arguments passed to Windows APIs (application programming interfaces)."

The vulnerability, which Gafa and his team discovered while writing a software testing application, is present in all versions of the Microsoft operating system dating back to Windows 2000, Mr Gafa added.

A Microsoft representative said the company was aware of the bug but downplayed the risk.

"Our initial assessment of the report is that malicious code would have to already be running or a user would have to be able to run a specially crafted application to cause the system to crash," a company spokesperson told SCMagazineUS.com on Wednesday in an email. "In either case, the system has already been compromised or the user has rights to logon to the system."

Sign up to our free newsletters

Get the best updates straight to your inbox:

You can unsubscribe at any time by clicking the link in the footer of our emails. We use Mailchimp as our marketing platform. By subscribing, you acknowledge that your information will be transferred to Mailchimp for processing.