Please wait while the page is being loaded Skip this advertisement >
Saturday | 6 December, 2008
Vista hole opens door to 'shout hacking'
Security honeymoon ends with warning on speech recognition
Paul F. Roberts (InfoWorld) 02/02/2007 09:19:44

The honeymoon ended early for Microsoft's Vista operating system, after word spread Wednesday about a flaw that could allow remote attackers to take advantage of the new operating system's speech recognition feature.

Microsoft researchers are investigating the reports of a vulnerability that could allow an attacker to use the speech recognition feature to run malicious programs on Vista systems using prerecorded verbal commands, the company said in an e-mail statement.

The potential security hole was discovered after an online discussion prompted blogger George Ou to try out a speech-based hack. Ou reported on ZD Net on Tuesday that he was able to access the Vista Start menu and, conceivably, run programs using voice commands played over the system's speakers.

The speech recognition flaw is novel and notable for being the first publicized hole in the new operating system since the public launch of Vista on Tuesday.

The impact of the flaw, however, is expected to be small. Vista users would need to have the speech recognition feature enabled and have a microphone and speakers connected to their system. Successful attackers would need to be physically present at the machine, or figure out a way to trick the computer's owner to download and play an audio recording of the malicious commands. Even then, the commands would somehow have to be issued without attracting the attention of the computer's owner.

Finally, attackers' commands are limited to the access rights of the logged on user, which may prevent access to any administrative commands, Microsoft said in a statement.

Microsoft recommends that users who are concerned about having their computer shout-hacked disable the speaker or microphone, turn off the speech recognition feature, or shut down Windows Media Player if they encounter a file that tries to execute voice commands on their system.

Customers who believe they have been shout-hacked can contact Microsoft Product Support Services, the company said.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about Microsoft
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose

Your organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links