Symantec offers mixed grades for Vista security

28.02.2007

"Microsoft has made good strides with kernel protection, but again, it's not perfect," Whitehouse said. "PatchGuard has and will be broken, and while it is obviously better than nothing, people who have an interest will find ways to get around these features."

Another area where Symantec leveled criticism at Microsoft is in relation to Vista's ASLR (Address Space Layout Randomization) feature, which is designed to help obscure programs stored in the operating system's memory to make it harder for attackers to isolate vulnerabilities. Symantec said the feature has a flaw that prevents it from working properly.

Here again, Symantec mixed praise and calls for concern in outlining its observations of ASLR.

"When implemented correctly, this technology is extremely effective in mitigating the exploitation of memory corruption and memory manipulation vulnerabilities," reads the Symantec report.

However, the research contends that Symantec has already found that one element of ASLR that means to randomize and hide software components does not work consistently, therein making it easier for attackers to guess where vulnerabilities may lie.