Windows Vista Release Candidate 2 frustrates this attack by blocking write-access to raw disk sectors for user mode applications, even if they are executed with elevated administrative rights. Rutkowska writes that Microsoft's fix is fraught with difficulties because it prevents legitimate applications, such as disk editors and recovery tools, from functioning without their own signed kernel-level driver.
As the article brings out, the fix blocks one door, but another could potentially swing open. Instead of using the standard methods, now certain drivers (such as IDE or SATA drivers) may be attacked, looking for a way around the block. According to some, Microsoft was presented with other, easier solutions, but opted for this. Will that be their ultimate choice? If so, it will mean that many programs, such as defragmenters will have to be rewritten in order to function.