:Windows Vista Security 'Rendered Useless' by Researchers
Windows Vista Security 'Rendered Useless' by Researchers Aug 8, 2008, 21 :44 UTC (10 Talkback[s]) (6489 reads)
""This stuff just takes a knife to a large part of the security mesh Microsoft built into Vista," Dai Zovi said. "If you think about the fact that .NET loads DLLs into the browser itself and then Microsoft assumes they're safe because they're .NET objects, you see that Microsoft didn't think about the idea that these could be used as stepping stones for other attacks. This is a real tour de force.""
Update: here is the PDF of the study the article is based on -- ed.