Microsoft boasts that Windows Server 2008 is the most secure Windows sever yet, but a researcher who put it to the test claims the product isn't as ironclad as advertised.
Cesar Cerrudo, founder and CEO of Argeniss Information Security in Argentina, said he'll show off flaws he discovered April 17 at the HITBSecConf2008 in Dubai during a presentation entitled "Token Kidnapping."
Windows Server 2008 does include a host of security improvements, he said. Nevertheless, Cerrudo said he found design flaws Microsoft engineers failed to catch during its Security Development Lifecycle (SDL). The flaws allow accounts commonly used by Windows to bypass new Windows services protection mechanisms and elevate privileges to achieve complete control over the operating system.