Bug in Windows Aero May Be Exploitable

Microsoft Security Response Center is warning of a flaw in Windows 7-x64 and Windows Server 2008 R2-x64 that could permit remote code execution. Although the bug affects users of the “Aero” theme on either platform, since “Aero” is off by default in Windows 2008 Server R2, this is primarily a threat for Windows 7-x64, where it is enabled by default.

Microsoft’s disclosure indicates they believe that the probability of exploit is low, but recommend that:

In the meantime, customers may choose to disable Windows Aero as a workaround to protect against potential threats. With Aero disabled, the path by which cdd.dll can be exploited is bypassed.

For more info, you can enjoy Slashdot’s coverage and PC Pro’s report as well.

1 comment to Bug in Windows Aero May Allow Remote Exploit

You must be logged in to post a comment.