<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Vista Vulnerability report published for Year 1</title><link>http://blogs.technet.com/mbullock/archive/2008/04/16/vista-vulnerability-report-published-for-year-1.aspx</link><description>Folks, I thought you might be interested in this report that has just been issued compiling the first year's worth of security vulnerability's found in Windows Vista, and comparing Windows&amp;#160; XP and non-Microsoft OS's first year vulnerabilities. The</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Vista Vulnerability report published for Year 1</title><link>http://blogs.technet.com/mbullock/archive/2008/04/16/vista-vulnerability-report-published-for-year-1.aspx#3038202</link><pubDate>Thu, 17 Apr 2008 00:28:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3038202</guid><dc:creator>tony</dc:creator><description>&lt;p&gt;yes I believe MS is doing a great job of securing their new products but I don't like the comparisons to other products rhel has a higher number of total sec vulns but how many are remotely exploitable how many are elevation issues.. ? I'm not worried about local exploits cause if your on the box u own it anyway. &amp;nbsp;But like I said MS is still doing a great job, keep up the good work!&lt;/p&gt;</description></item><item><title>Vista Vulnerability report published for Year 1 | Windows Guides | Mintywhite.com</title><link>http://blogs.technet.com/mbullock/archive/2008/04/16/vista-vulnerability-report-published-for-year-1.aspx#3038385</link><pubDate>Thu, 17 Apr 2008 08:00:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3038385</guid><dc:creator>Vista Vulnerability report published for Year 1 | Windows Guides | Mintywhite.com</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://mintywhite.com/tech/news/vista-vulnerability-report-published-for-year-1/"&gt;http://mintywhite.com/tech/news/vista-vulnerability-report-published-for-year-1/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Vista Vulnerability report published for Year 1</title><link>http://blogs.technet.com/mbullock/archive/2008/04/16/vista-vulnerability-report-published-for-year-1.aspx#3038574</link><pubDate>Thu, 17 Apr 2008 15:07:31 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3038574</guid><dc:creator>Mark Sowul</dc:creator><description>&lt;p&gt;You shouldn't ignore local exploits - a seemingly innocuous elevation-of-privilege vulnerability can turn a remote access vulnerability into complete control of the machine.&lt;/p&gt;
&lt;p&gt;For example: would you rather have two hypothetical IIS vulnerabilities that let you execute code in the context of the IIS account (these would probably be marked &amp;quot;important&amp;quot; or &amp;quot;critical,&amp;quot; or would you rather have one such vulnerability (&amp;quot;important&amp;quot;/&amp;quot;critical&amp;quot;) and one local elevation-of-privilege vulnerability (probably would be marked as &amp;quot;low&amp;quot; or &amp;quot;important&amp;quot;)?&lt;/p&gt;
&lt;p&gt;In the first case, the damage is non-trivial, but limited because the IIS account would have few privileges on its own. &amp;nbsp;In the second, you could piggyback the EoP on top of the remote vulnerability, and now you own the whole machine.&lt;/p&gt;</description></item><item><title>Vunerabilidades do Vista 1 ano depois do lançamento</title><link>http://blogs.technet.com/mbullock/archive/2008/04/16/vista-vulnerability-report-published-for-year-1.aspx#3038706</link><pubDate>Thu, 17 Apr 2008 17:46:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3038706</guid><dc:creator>Inside Microsoft</dc:creator><description>&lt;p&gt;Diferen&amp;#231;a grande se comparado com o XP. Metric Windows Vista (1 year) Windows XP (1 year) Vulnerabilities&lt;/p&gt;
</description></item><item><title>Internet Explorer Security Patch</title><link>http://blogs.technet.com/mbullock/archive/2008/04/16/vista-vulnerability-report-published-for-year-1.aspx#3170898</link><pubDate>Thu, 18 Dec 2008 20:16:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170898</guid><dc:creator>Malcolm Bullock - Optimising Infrastructure for business benefit</dc:creator><description>&lt;p&gt;This isn't something that I would normally bother blogging on - and from the lack of recent posts you&lt;/p&gt;
</description></item></channel></rss>