Disable Windows Sidebar and Gadgets NOW on Vista and Windows 7. Microsoft warns

Spirit

Level 2
Thread author
May 17, 2012
1,832
Disable Windows Sidebar and Gadgets NOW on Vista and Windows 7. Microsoft warns of security risk


Microsoft has warned that a Gadgets feature included in Vista and later versions of Windows could allow attackers to hijack end-user machines and has taken the unusual step of issuing a temporary update that allows it to be completely disabled.

"An attacker who successfully exploited a Gadget vulnerability could run arbitrary code in the context of the current user," company officials said in an advisory issued Tuesday. "If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system." To be successful, they added, "An attacker would have to convince a user to install and enable a vulnerable Gadget."

Microsoft added the Gadgets feature and an accompanying Sidebar to Windows Vista in hopes of matching the success Apple had with a similar feature called Dashboard, which is included in Mac OS X. It allows end users to add clocks, stock tickers, and other small apps to their desktops. A few weeks ago, Microsoft pulled the plug on its official Gadgets gallery. The page now includes a warning that says, "Gadgets installed from untrusted sources can harm your computer and can access your computer's files, show you objectionable content, or change their behavior at any time."

An accompanying Fix-it, which users are free to use or ignore, is described as a "workaround" and completely disables the Windows Sidebar and Gadgets.

Microsoft didn't elaborate on the vulnerability or its long-term plans for Gadgets. Tuesday's advisory thanked "Mickey Shkatov and Toby Kohlenberg for working with us on Gadget vulnerabilities." The researchers are scheduled to deliver a presentation on July 26 at the Black Hat security conference in Las Vegas titled "We Have You by the Gadgets."

source

Clearly Microsoft is worried about the security researchers' findings, and has issued a "Fix It Tool" which will protect Windows 7 and Vista users by entirely disabling the Windows Sidebar and Gadgets functionality.

Fix it Tool

More Here
 
D

Deleted member 178

i disabled my Windows Gadget Plateform since a while ago.
 

Spirit

Level 2
Thread author
May 17, 2012
1,832
umbrapolaris said:
i disabled my Windows Gadget Plateform since a while ago.

The first step I do after windows install :
Turn Windows defender off,system restore off,windows gadget off.
 

Spirit

Level 2
Thread author
May 17, 2012
1,832
umbrapolaris said:
also Hibernation -off

yes i do many other manual settings like remote desktop off remote registry off and other stuffs but the above three are the 1st step I do :D
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
Ha, don't use any of the gadgets. Just use the good old Rainmeter. Does what any other gadget would do, but mum uses the little sticky notes, so will have to let her know about it.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
Thanks for the heads up, now I have to head out to disable it. :(




You don't sleep for months at a time? :huh:

umbrapolaris said:
also Hibernation -off
 
D

Deleted member 178

because it uses lot of space on HDD and i never use it, when i finish , i shut down my computer.
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
umbrapolaris said:
because it uses lot of space on HDD and i never use it, when i finish , i shut down my computer.

Have to say, I do the same as well. Once finished or going to TAFE normally turn it off.
 
N

Nige_40

(remote registry off) That seems to be already off on my system. I wonder if that is a Windows 7 default of having it off ?
 

Spirit

Level 2
Thread author
May 17, 2012
1,832
Nige_40 said:
(remote registry off) That seems to be already off on my system. I wonder if that is a Windows 7 default of having it off ?

No its not default off in windows 7
 
N

Nige_40

Stranger said:
Nige_40 said:
(remote registry off) That seems to be already off on my system. I wonder if that is a Windows 7 default of having it off ?

No its not default off in windows 7

That's Strange that! mine was turned off. It must of been Boost speed by Auslogics fixed it for me ??

anyway thanks for the feedback

Regards
Nigel
 

Littlebits

Retired Staff
May 3, 2011
3,893
I don't believe sidebar gadgets are a serious vulnerability.

Most users don't read security bulletins therefore if this was a serious problem Microsoft would push out a fix with Windows Updates.

Microsoft would not leave serious vulnerabilities unpatched.

The only reason why Microsoft posted this security bulletin and disabled their gadget gallery is to make the paranoid users feel more secure and satisfy credits.

I don't recall reading any news about a hacker taking advantage of this vulnerability.

There are many download sites and developer sites where you still can download trusted gadgets. If this was a serious issue, these sites would remove their gadgets.

I love my sidebar gadgets and will continue to use them.

I believe this was a very poor move for Microsoft, users paid for Windows Sidebar as a part of the listed features. Disabling this feature is no way to fix a problem.

Thanks.:D
 

pcjunklist

Level 1
Dec 28, 2011
523
I guess we will have to wait until July 26th to see what comes out at the Blackhat Conference. They are such a waste of system resources anyways.

Also this thread is a re-post from the 11th.
http://malwaretips.com/Thread-Windows-Widgets-Security-Hole-Discovery
 

Spirit

Level 2
Thread author
May 17, 2012
1,832
Nige_40 said:
Stranger said:
Nige_40 said:
(remote registry off) That seems to be already off on my system. I wonder if that is a Windows 7 default of having it off ?

No its not default off in windows 7

That's Strange that! mine was turned off. It must of been Boost speed by Auslogics fixed it for me ??

anyway thanks for the feedback

Regards
Nigel

Auslogic Bootspeed Turn off many useless and unprotected service like auto run,administrative shares and its look that remote registry of your pc is turn off by auslogic.

You are using a good maintenance software :Auslogic bootspeed
 
D

Deleted member 178

i removed my gadgets since they used around 20% of CPU usage and around 30mb RAM.
 

Spirit

Level 2
Thread author
May 17, 2012
1,832
umbrapolaris said:
i removed my gadgets since they used around 20% of CPU usage and around 30mb RAM.

If that much of cpu/ram i have to sacrifice i will go with rainmeter and its theme + nexus products
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top