Evaluating the Security of Vista Kernel Mode [1]

by nagual on 2007-03-26 10:43:45

**Assessment of Windows Vista Kernel-Mode Security**

*Matthew Conover, Principal Security Researcher, Symantec Corporation*

*Translated by 7all (www.cisrg.cn)*

**Abstract—** Windows Vista introduces several additional barriers designed to prevent malicious code from gaining access to the operating system kernel. This paper aims to provide a technical review of their implementation. The kernel-mode security enhancements in Windows Vista are quite significant, leading to a substantial reduction in its overall attack surface. However, we have identified certain weaknesses in the kernel improvements that could potentially be exploited by malicious code to undermine these advancements.