再谈Issue regarding Windows Vista Speech Recognition (Windows Vista语音识别命令执行漏洞)
来源:互联网 发布:迅雷mac历史版本下载 编辑:程序博客网 时间:2024/04/19 09:10
Windows Vista是微软公司开发的最新的操作系统。
Windows Vista内置的语音识别功能存在安全问题,远程攻击者可以利用漏洞在目标用户机器上执行任意命令。
在Vista上起用了语音识别功能及正确配置后,攻击者可以利用音频文件对系统发布类似“copy”, “delete”, ”shutdown”等命令,不过如果用户在电脑前面,也会听到这些命令的发布。不过使用语音命令不能绕过UAC提示来执行类似建立用户等特权功能。
Sebastian Krahmer(漏洞发现者)博客的原文 :
Hey everyone this is Adrian and I am writing to try and clear up some concerns regarding a recently reported vulnerability in the Speech Recognition feature of Windows Vista. An issue has been identified publicly where an attacker could use the speech recognition capability of Windows Vista to cause the system to take undesired actions. While it is technically possible, there are some things that should be considered when trying to determine what the threat of exposure is to your Windows Vista system.
In order for the attack to be successful, the targeted system would need to have the speech recognition feature previously activated and configured. Additionally the system would need to have speakers and a microphone installed and turned on. The exploit scenario would involve the speech recognition feature picking up commands through the microphone such as “copy”, “delete”, ”shutdown”, etc. and acting on them. These commands would be coming from an audio file that is being played through the speakers. Of course this would be heard and the actions taken would be visible to the user if they were in front of the PC during the attempted exploitation. It is not possible through the use of voice commands to get the system to perform privileged functions such as creating a user without being prompted by UAC for Administrator credentials. The UAC prompt cannot be manipulated by voice commands by default. There are also additional barriers that would make an attack difficult including speaker and microphone placement, microphone feedback, and the clarity of the dictation.
You may ask why this is new to Windows Vista as previous versions of the operating system do not appear affected. Windows Vista’s sophisticated speech recognition allows for easier operation and extended support for commands. This has been largely used to help facilitate computing use especially for users that are affected by dexterity difficulties or impairments. You can learn more about Windows Vista’s accessibility tools including speech recognition by going to http://www.microsoft.com/industry/healthcare/providers/businessvalue/housecalls/accessibletech.mspx.
While we are taking the reports seriously and investigating them accordingly I am confident in saying that there is little if any need to worry about the effects of this issue on your new Windows Vista installation.
-Adrian
- 再谈Issue regarding Windows Vista Speech Recognition (Windows Vista语音识别命令执行漏洞)
- 一个基于Windows Vista speech API5.3以及WPF技术的语音识别代码
- Windows Vista的漏洞
- Speech.Recognition(语音识别)
- 基于vc++2008托管代码开发Windows Vista语音识别
- 一个基于Windows Vista speech API5.3以及WPF技术的语音朗读代码
- Microsoft Vista Speech Recognition Tested - Perl Scripting
- 探究 Windows Vista 中新的语音识别与合成 API
- 探究 Windows Vista 中新的语音识别与合成 API(转)
- 探究 Windows Vista 中新的语音识别与合成 API(转)
- 语音识别综述 awesome-speech-recognition-speech-synthesis-papers
- Windows Vista下面的一些命令
- Windows Vista中的新命令完整版
- 基于vc++2008托管代码开发Windows Vista语音朗读
- Windows Vista曝近3万处漏洞
- Microsoft Windows Vista DHCP远程拒绝服务漏洞(MS08-004)
- Longhorn 又名 Windows Vista
- Windows Vista谐音
- 入侵了2天终于搞定平和学校的网站了。
- 一些eclipse插件网站
- GDB调试精粹及使用实例
- .NET和Java将有更好的动态语言支持(翻译)
- Tips:IE脱掉 脱掉 通通脱掉~~~``
- 再谈Issue regarding Windows Vista Speech Recognition (Windows Vista语音识别命令执行漏洞)
- 转:熊猫烧香delphi实现代码
- Web Storage System + WebDAV
- 将java程序运行为Windows服务
- 最近学习VB.NET
- JDOM 介绍及使用指南
- 今天博了
- javascript window.open后不出现[object]的方法
- XNA Kick Start (三)