Malta researchers find Windows bug that crashes PCs

Share this article:

Researchers at a software company in Malta say they have discovered a decade-old Windows vulnerability that can cause a system to instantly crash and display the so-called blue screen of death.

The denial-of-service condition can result if a user is tricked into running an application that contains the malicious code, Paul Gafa, CTO of 2X Software, told SCMagazineUS.com on Wednesday.

"You can be the least privileged user on the system and still crash it," he said. "I believe it is very easy for Microsoft to sort it out. They just need to validate arguments passed to Windows APIs (application programming interfaces)."

The vulnerability, which Gafa and his team discovered while writing a software testing application, is present in all versions of the Microsoft operating system dating back to Windows 2000, Gafa added.

A Microsoft representative said the company was aware of the bug but downplayed the risk.

"Our initial assessment of the report is that malicious code would have to already be running or a user would have to be able to run a specially crafted application to cause the system to crash," a company spokesperson told SCMagazineUS.com on Wednesday in an email. "In either case, the system has already been compromised or the user has rights to logon to the system."

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

FilmOn accuses DoubleVerify of distributing malware

In readying a libel suit against DoubleVerify, FilmOn says it discovered that the firm deliberately distributed malware.

Schumer: Feds should do 'top to bottom' probe of online drug marketplaces

Sen. Charles Schumer of New York has called on federal law enforcement officials to stop "copy cat websites."

ShellShock vulnerability exploited in SMTP servers

Researchers at Trend Micro found that attackers were targeting Simple Mail Transfer Protocol (SMTP) servers to execute malicious code and an IRC bot.