Microsoft talks down speech recognition bug

  • Email a Friend
  • Print Page
Microsoft talks down speech recognition bug
Related Listings
By Clement James
Feb 5, 2007 9:22 AM
Tags: Microsoft | talks | down | speech | recognition | bug

Vista feature could be used to hijack a PC.

Microsoft has admitted that the speech recognition feature in Windows Vista could be used to hijack a PC running the operating system.

The company said in a posting on the Microsoft Security Response Centre blog that an issue has been identified in which an attacker could use the speech recognition capability to cause the system to take "undesired actions".

"While it is technically possible, there are some things that should be considered when trying to determine the threat of exposure to your Windows Vista system," the posting said.

In order for the attack to be successful, Microsoft claimed that the targeted system would need to have the speech recognition feature previously activated and configured.

The system would also need to have speakers and a microphone installed and turned on.

The exploit would involve the speech recognition feature picking up commands through the microphone such as 'copy', 'delete' or 'shutdown'.

The vulnerability relies on commands coming from an audio file being played through the speakers, and the actions taken would be visible to the user if they were in front of the PC during the attempted exploitation.

It is not possible through the use of voice commands to get the system to perform privileged functions, such as creating a user, without being prompted by Microsoft's User Account Control (UAC) for Administrator credentials. 

"The UAC prompt cannot be manipulated by voice commands by default," said the blog posting.

"There are also additional barriers that would make an attack difficult, including speaker and microphone placement, microphone feedback and the clarity of the dictation."
 

Copyright © 2009 vnunet.com

 


Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment


Top Stories
Internode MD in green car race
Internode founder and managing director Simon Hackett will drive his Tesla Roadster electric sports car in the Global Green Challenge.
 
Alphawest to deliver VMware vCloud Beta
The ICT (Information and Communications Technology) provider will run a pilot program with a select group of Australian customers.
 
Panasonic finds plasma distributor
Panasonic Business Systems has partnered with GBI Sales to distribute its Premiere Home Theatre Plasma Series.
 

Shortcutsall you need to know on...

  • NBN 
  • Windows 7 
  • Unified Communications 
  • Twitter 
  • Virtualisation 

Latest Comments

"Hi Cecil, Tony Lagan from Sony made it clear that is the very case. Thanks for your input. "
by lguan Jul 1, 2009 6:33 PM
 
"Cool, I shall jump in my DeLorean right away, and head off to the Google developer day :-) Back ..."
by jgcertified Jun 30, 2009 10:11 PM
 
"A key issue for organisations is the complexity of licensing, particularly with the wide range ..."
by easysam Jun 30, 2009 6:50 PM
 
"All these $150-$200 predictions assume that $40 million will be paid by home and small business ..."
by peterh_oz Jun 30, 2009 5:06 PM
 
"I read eon below link unencrypting takes along time and another limitation appears to be if ..."
by kWAT Jun 30, 2009 9:56 AM
 

Polls

Has dealing with email security become easier?


   |   View results
The war on junk viruses is never ending, just when one thing is fixed another pops up
  36%
 
Hardware and software has become better at dealing with spam, fake email and virus attachments
  40%
 
Users are the key to dealing with email deluge they just need to be smarter about it
  24%
TOTAL VOTES: 58

Vote now

CRN Magazine

Issue: 268 | June, 2009

CRN Magazine looks in-depth at the emerging issues and developments for the Channel, and provides insight, analysis and strategic information to help resellers better run their businesses.