Otkrivena je sigurnosna ranjivost u operacijskom sustavu Microsoft Windows. Zlonamjerni lokalni korisnici mogu iskoristiti spomenutu ranjivost za izvođenje napada uskraćivanjem usluge (eng. Denial of Service).
Paket:
Microsoft Windows XP
Operacijski sustavi:
Microsoft Windows XP
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
lokalno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
ne postoji zakrpa
Izvorni ID preporuke:
SA49021
Izvor:
Secunia
Problem:
Propust je posljedica pogreške u "xxxCreateWindowEx()" funkciji.
Posljedica:
Lokalni napadač može iskoristiti navedeni propust za izvođenje DoS napada pristupom neispravnim memorijskim lokacijama.
Rješenje:
Rješenje problema sigurnosti je omogućiti pristup samo pouzdanim korisnicima.
Secunia Advisory SA49021
Microsoft Windows win32k.sys Denial of Service Vulnerability
Release Date 2012-05-03
Criticality level Not criticalNot critical
Impact DoS
Where Local system
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia VIM
Operating System
Microsoft Windows XP Professional
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the "xxxCreateWindowEx()" function and can be exploited to access an invalid memory location resulting in a system crash.
The vulnerability is confirmed on a fully patched Windows XP SP3 (win32k.sys version 5.1.2600.6189). Other versions may also be affected.
Solution
Restrict access to trusted users only.
Provided and/or discovered by
Lufeng Li, Neusoft Corporation
Original Advisory
http://www.exploit-db.com/exploits/18819/
Posljednje sigurnosne preporuke