U radu operacijskog sustava Microsoft Windows XP otkrivena je sigurnosna pogreška koju lokalni zloćudni korisnik može iskoristiti za DoS napad.
Paket:
Microsoft Windows XP
Operacijski sustavi:
Microsoft Windows XP
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
lokalno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
zaobilazno rješenje (workaround)
Izvorni ID preporuke:
SA46919
Izvor:
Secunia
Problem:
Otkrivena je greška u upravljačkom programu win32k.sys pri učitavanju određenih datoteka. Ranjivost je potvrđena kod sustava Windows XP SP3 (win32k.sys inačica 5.1.2600.6149)
Posljedica:
Zlonamjeran, lokalni napadač može iskoristiti slabost kako bi pristupio navažećoj memorijskoj lokaciji i time uzrokovao DoS napad.
Rješenje:
Preporuča se ograničavanje pristupa samo pouzdanim korisnicima.
Microsoft Windows win32k.sys Driver Keyboard Layout Denial of Service
Secunia Advisory SA46919
Release Date 2011-11-22
Criticality level Not criticalNot critical
Impact DoS
Where Local system
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia VIM
Operating System
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
The vulnerability is caused due to an indexing error in the win32k.sys driver when loading a keyboard layout file. This can be exploited to access an invalid memory location resulting in a system crash.
The vulnerability is confirmed on a fully patched Windows XP SP3 (win32k.sys version 5.1.2600.6149). Other versions may also be affected.
Solution
Restrict access to trusted users only.
Provided and/or discovered by
instruder
Original Advisory
http://www.exploit-db.com/exploits/18140
Posljednje sigurnosne preporuke