Microsoft talks down speech recognition bug

By Clement James
Feb 5, 2007 9:22 AM
Tags: microsoft | talks | speech | recognition | bug

Vista feature could be used to hijack a PC.

Microsoft has admitted that the speech recognition feature in Windows Vista could be used to hijack a PC running the operating system.

The company said in a posting on the Microsoft Security Response Centre blog that an issue has been identified in which an attacker could use the speech recognition capability to cause the system to take "undesired actions".

"While it is technically possible, there are some things that should be considered when trying to determine the threat of exposure to your Windows Vista system," the posting said.

In order for the attack to be successful, Microsoft claimed that the targeted system would need to have the speech recognition feature previously activated and configured.

The system would also need to have speakers and a microphone installed and turned on.

The exploit would involve the speech recognition feature picking up commands through the microphone such as 'copy', 'delete' or 'shutdown'.

The vulnerability relies on commands coming from an audio file being played through the speakers, and the actions taken would be visible to the user if they were in front of the PC during the attempted exploitation.

It is not possible through the use of voice commands to get the system to perform privileged functions, such as creating a user, without being prompted by Microsoft's User Account Control (UAC) for Administrator credentials. 

"The UAC prompt cannot be manipulated by voice commands by default," said the blog posting.

"There are also additional barriers that would make an attack difficult, including speaker and microphone placement, microphone feedback and the clarity of the dictation."
  • Email a Friend
  • Print Page
Microsoft talks down speech recognition bug
Related Listings
 

Copyright ©v3.co.uk

 


Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment


Top Stories
Microsoft call to drop EBS “like a bombshell”
Hundreds of thousands of dollars in potential sales lost.
 
Case study: Ingram's Partner Technology Centre racks up fans
A unique demonstration facility is proving highly effective for resellers looking to show solutions to potential clients.
 
Managed print: Fix the doc and prosper
Generating documents eats away at companies’ margins in an insidious manner. Intelligent solutions can bring it all under control, writes Anthony Caruana
 
Shortcutsall you need to know on...
  • NBN 
  • Windows 7 
  • Unified Communications 
  • Smart Power 
  • Virtualisation 
Latest Comments
"At least someone has stood up to Oracle and its stance on opensource software. May be more will ..."
by wwwalker Mar 11, 2010 6:51 PM
 
"Actually, there seems to be an opportunity for a reseller with lots of ambition. What's to stop ..."
by bld Mar 11, 2010 1:46 PM
 
"This is all a big lie. We are a preferred IT supplier to the Insurance industry, shipping to ..."
by gscanlan@pc-deal.com Mar 11, 2010 1:32 PM
 
"To Linepower. The reasons for removing the copper cable are three fold. 1. Copper is expensive ..."
by Francis Mar 11, 2010 10:22 AM
 
"Yeah! Having just made my first claim for income insurance after my prostatectomy I have to say ..."
by spook1958 Mar 10, 2010 5:05 PM
Polls
How will Cisco's split with HP affect your business?



   |   View results
Not at all
  51%
 
A minor annoyance but no lasting effect
  10%
 
A big pain clearing stock and re-certifying
  9%
 
Cisco and HP? Never heard of them
  29%
TOTAL VOTES: 68

Vote now
CRN Magazine

Issue: 276 | February, 2010

CRN Magazine looks in-depth at the emerging issues and developments for the Channel, and provides insight, analysis and strategic information to help resellers better run their businesses.