Re: #litestep

"Jochen Ritzel" <[email protected]> Fri, 23 Jul 2010 16:16:19 +0200
Newsgroups gmane.comp.windows.shells.litestep
Message-ID <op.vgau9foxifobub@w00t>
Am 23.07.2010, 15:50 Uhr, schrieb Antoine W. Campagna  
<AntoineW-/[email protected]>:

>> http://support.microsoft.com/kb/2286198

> Well that's something, I thought it was a joke when reading it. Do they  
> recommend to everybody to install this fix ?

> But I am wondering how LS reads icons and maybe it's using the same  
> API/Library and would also be vulnerable.

Litestep runs with user privileges, but the Windows code that bug affects  
has higher privileges and this makes it a problem. This means that even if  
Litestep is affected, exploiting this only means you can delete everything  
of the current user -- something any Litestep theme can do by default :P

The workaround simply disables all icons, so it's not really a fix. As  
long as you don't open anything from sources you cannot absolutely trust  
(as always), you're as safe as you can get with Windows ;-)

Jochen

---------------------------------------------------------------------
    Can't Unsubscribe? Check http://desktopian.org/listunsub.html
        LS List Homepage: http://wuzzle.org/list/litestep.php
            Get the LS FAQ: http://lsfaq.shellfront.org