NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Medium Rating for Vista MessageBox Vulnerability

Fully functional PoC has been published on December 31

By Marius Oiaga, Technology News Editor

4th of January 2007, 11:44 GMT

Adjust text size:


The vulnerability affecting the Client Server Run-Time Subsystem in Windows Vista, but also other operating systems from Microsoft including Windows 2000 SP4, Windows Server 2003
SP1, Windows XP SP1, Windows XP SP2, has received a medium risk assessment level from McAfee.

Microsoft has confirmed both the vulnerability and the existence of exploit code in the wild since December 20, 2006, but has failed to issue a patch addressing the flaw. The Redmond Company's slow reaction to patch a vulnerability that is spread across an array of its operating environments is illustrative of the moderate risks associated with the flaw. The fact that exploit code was available as early as December 20, and the Proof-of-Concept code was published on December 31, without resulting in widespread attack is another argument which ensures that a successful exploit will not have a major impact on the operating system.

The NtRaiseHardError PoC published on the last day of 2006, has been tested by eEYE Research and was confirmed as a fully functional public Zero-day Windows Vista exploit. eEYE Research has also attributed a medium risk level to the vulnerability. However, eEYE Research claims that a successful exploit of this vulnerability allows for local elevation of privilege on the affected operating systems and that this will permit remote code execution.

"Although this vulnerability requires an attacker to already be logged in or executing other code on a host, this does allow for the attacker to elevate his/her privileges to SYSTEM, allowing for complete system compromise no matter what credentials were used launch this vulnerability," revealed eEYE Research.

McAfeem reveals that the vulnerability conducts to privilege escalation without user interaction, and states that another alternative is a denial of service attack.

"The Microsoft Windows MessageBox API allows for messages to be sent by non-interactive services to the Windows Client/Server Runtime Server Subsystem (CSRSS) to alert of an error. A vulnerability exists in Microsoft Windows Client/Server Runtime Server Subsystem (CSRSS) that may allow for a local denial of service or privilege escalation. The flaw lies in processing of specially-crafted LPC requests which begin with a "??" or contain a "Device" ANSI string, sent by the MessageBox function. Code execution resulting from successful exploitation would be at SYSTEM level," reads McAfee's description of the vulnerability.
Read by 1,104 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.0/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Anytime Upgrade

Windows Vista Is Plagued with Vulnerabilities

Trojans Spread Via Zero-Day Word Vulnerability

Disable Tabbed Browsing in Internet Explorer 7

Merry Vista Vulnerability!

100,000 Computers Looking for Porn

Internet Explorer Sinks Under 80%

Microsoft's "Very Limited, Targeted Attacks"

Mass Mailing Worm Greets the New Year

The First Windows Vista Vulnerability

Inspect OS and Software Security

Seven December 2006 Security Bulletins

PoC Published for Internet Explorer 7 Vulnerability

Yes, Sophos Already Released Vista Anti-virus Protection

Vista Is Neither Foolproof Nor Perfect

Windows Live OneCare Released to Manufacturing

Attack Vectors in Windows Vista

64-bit Windows Vista Timer Stopper Crack Available

OneCare Will Add Vulnerabilities to Windows Vista

The Limitations of Extended Validation SSL Certificates

Exchange Server 2007 White Paper

Microsoft Warns of Zero-Day Attacks

Microsoft Confirms Vista Activation Breach

Firefox 2.0 Continues to Grow in the Detriment of IE7

133 Critical and Important Microsoft Vulnerabilities

Managing Multiple Home Tabs in IE7

Could Microsoft Have Controlled the Vista Vulnerabilities?

Windows Vista Is Immune to Existing Malware

A Windows Vista Zero-Day Exploit Costs $50,000

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM