Flaw or not, Microsoft to release a patch

eWeek | at | by Mike

Microsoft is working on patches for several services within Windows that run with inappropriately high privileges, making the operating system vulnerable to a sophisticated attack that could lead to a complete compromise of the machine.

"This really is not a security model flaw because you can clearly implement a program not to be vulnerable to this. Higher privileged programs such as services running as system should not be taking input from lower privileged users without filtering it," said Chris Wysopal, director of research and development at @stake Inc., a security consultancy and research firm in Cambridge, Mass. "Windows messages need to be thought of as untrusted input just like network traffic. I would consider this an application design error. I think that the controversy over this is because people can't agree to whether or not the OS should be protecting applications from malicious inter-process messages. Windows does not document that the system protects from this. It is up to the application developer."