Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 13th, 2011, 13:55 GMT · By

Microsoft Patches Critical Vulnerability in Bluetooth Stack

SHARE:

Adjust text size:


Critical vulnerability patched in Windows Bluetooth stack
Enlarge picture
Microsoft has released its July batch of security patches which address vulnerabilities in Windows and Office, including a one that allows for remote code execution.

Identified as CVE-2011-1265, the vulnerability is covered in MS11-053, the only Microsoft security bulletin rated critical this month.

It is located in the Windows Bluetooth stack and affects all supported versions of Windows Vista and 7. Obviously, the vulnerability can only be exploited on computers that contain Bluetooth controllers.

"The vulnerability could allow remote code execution if an attacker sent a series of specially crafted Bluetooth packets to an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft writes in its advisory.

Despite this security issue being rated as critical, Microsoft security researchers believe that it would be hard to build a reliable exploit for it. They note that denial of service attacks are more likely than the execution of arbitrary code.

Furthermore, finding the Bluetooth address required for a successful attack is not straight forward because Windows 7 computers are not configured to be "discoverable" by default.

But even if an attacker would find out the address, they wouldn't be able to exploit the vulnerability over the Internet. A successful attack requires the victim to be in the line of sight.

"This combination of factors leads us to believe that systems are unlikely to be exposed to reliable remote code execution exploits via this vulnerability in the next 30 days," Jonathan Ness from the MSRC Engineering team says.

In addition to this security bulletin, Microsoft released three more, all of them rated important. They address fifteen privilege escalation flaws in the Windows kernel-mode drivers, five EoP vulnerabilities in the Windows Client/Server Run-time Subsystem (CSRSS) and a publicly disclosed remote code execution hole in Microsoft Visio.

Users and system administrators are advised to deploy the patches as soon as possible, however, those who can't should at least disable the ability of Bluetooth devices from connecting to their computers. This can be done from the Bluetooth Settings panel by unchecking "Allow Bluetooth devices to connect to this computer."

TELL US WHAT YOU THINK:

992 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Recently Patched IE Flaw Exploited in the Wild

Microsoft to Partially Patch Cookiejacking Flaw Next Week

Microsoft Suggests Using Private Browsing Mode Until IE Cookiejacking Patch

Microsoft Sidesteps Office for Mac on Patch Tuesday

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM