Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Windows Gadgets. Yes or No?


07 May 2014   #1

Windows 7
 
 
Windows Gadgets. Yes or No?

Dled these 2 gadgets from here:

http://www.myfavoritegadgets.info/cl...nDownload.html

which are the same files hosted on softpedia.

scanned both files and found no virus:

https://www.virustotal.com/en/file/7...is/1399459303/

https://www.virustotal.com/en/file/6...is/1399459294/

SO it's it safe to run these or do they have vulnerabilities ?

https://technet.microsoft.com/library/security/2719662

My System SpecsSystem Spec
.

07 May 2014   #2

Windows 7 Professional 64-bit
 
 

I cant see any problems with them.
My System SpecsSystem Spec
07 May 2014   #3

Windows 7 Ultimate x64
 
 

It's really difficult to tell just by the technet article, since it gives little details on what the vulnerabilities actually are, it just states that disabling gadgets altogether is the recommended solution, but far from ideal in the real world.

My impression based on the few indications given on the two points from the article are that the gadget can either run arbitrary code from inside the computer or it might be commanded to do so from an attacker.

Your virus scan probably says local execution is safe, but for the outside "attacker" I think you can mitigate that eventual hole by firewalling sidebar.exe off the internet to be extra sure.

Other than that, together with usual precautions of low privileges/antivirus/firewall/common sense, I don't see anything bad with it, as long as you trust the author.
My System SpecsSystem Spec
.


07 May 2014   #4

Windows 7 Professional x64 Sp1
 
 

Via the white paper here:

http://media.blackhat.com/bh-us-12/B...Gadgets_WP.pdf

The vulnerability involves the fact that any gadget that connects to the internet can be compromised, and gain control over the system. So for example, the built in windows 7 cpu gadget is not vulnerable, but the weather gadget is.

There has not been any wide or known history of this being used in the wild however. But it can be done. Third party gadgets are more vulnerable due to the fact that they are not typically built with security in mind.

An easy way to avoid the vulnerabilities if you are worried, is to use turn off gadgets in turn windows features on or off in the control panel under programs and features. Then uncheck gadgets, click OK and restart.

Microsoft also has a patch about it, which can be found here:

Microsoft Security Advisory: Vulnerabilities in Gadgets could allow remote code execution

Here is the interesting bit though:

If this vulnerability is bad like it states, why is it not offered in windows update? That my friends, is the real question. It is not even offered in the optional updates.

Due to this, I think the likely hood of this attack being carried out is a small risk, and I use gadgets.

Remember though: Nothing is 100% secure. Just because you disable gadgets, does not mean there is not another way into your pc. But if you are paranoid and want to be as safe as possible, disable them.
My System SpecsSystem Spec
Reply

 Windows Gadgets. Yes or No?




Thread Tools




Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 04:10 AM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33