Is Microsoft's Bluetooth bug 'all bark and no bite?'
Tue, 2008-06-10 22:49

MIcrosoft rated the bug "critical, but members of the company's Secure Windows Initiative team are saying that a recently patched Bluetooth vulnerability is not such a big deal.

The bug could theoretically allow attackers to run code and PWN your system, but in a post entitled, "MS08-030: All bark and no bite? The case of the Bluetooth update," the SWI team said that MS08-030 is not one of those "the sky is falling" updates.

They gave three reasons for their conclusion:
1) You've got to be pretty close -- a few yards at best -- in order to make a Bluetooth connection.
2) There's a narrow window of opportunity to sent the malicious message that would trigger this bug."Based on our investigation, a single-processor machine is unlikely to be affected by this issue," the SWI team writes
3)The attacker must place their data in the computer's memory within this narrow window.

"The information above is presented to help customers understand that the “sky is not falling” in terms of immediate risk due to this vulnerability. That said, we still recommend customers patch any affected systems, especially those that have Bluetooth enabled," they write.

AttachmentSize
childs_complaint.pdf63.09 KB
Ads by TechWords
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WHITE PAPER
Maximizing Site Visitor Trust Using Extended Validation SSL

VeriSignNow with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in the free VeriSign white paper.

» Read the Paper