Cyber seCurity fundAmentAls 51
allow privilege escalation. According to Paget, the Microsoft fixes
for this vulnerability only disable certain vulnerable functions but do
little to prevent the privilege escalation vulnerabilities in the window-
messaging system.
1.2.2.2 Solving Problems with Window Messages Windows Vista is
less susceptible to shatter attacks due to greater separation of inter-
active sessions. In Vista, users log on to user sessions starting at one
instead of zero (which Vista reserves for system services). In this way,
user applications cannot interact with system services that previously
exposed their window-messaging functionalities. Microsoft has fixed
problems related to privilege escalation in many of its own ...