OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] Windows Kernel Privilege Escalation Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Wed Apr 16 2003 - 13:31:07 CDT


TITLE:
Windows Kernel Privilege Escalation Vulnerability

READ ONLINE:
http://www.secunia.com/advisories/8609/

CRITICAL:
Less critical

IMPACT:
Privilege escalation

WHERE:
Local system

OPERATING SYSTEM:
Microsoft Windows 2000 Server
Microsoft Windows NT 4.0 Server, Terminal Server Edition
Microsoft Windows NT 4.0 Server
Microsoft Windows XP Home Edition
Microsoft Windows NT 4.0 Workstation
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Advanced Server
Microsoft Windows XP Professional
Microsoft Windows 2000 Datacenter Server

DESCRIPTION:
A vulnerability has been identified in some versions of Windows,
which can be exploited by malicious users on a vulnerable system to
escalate their privileges.

The vulnerability is caused by a boundary error in the kernel due to
a flaw in the way error messages are passed to debuggers. A malicious
user can exploit this by running a specially crafted program, which
causes a buffer overflow by sending malformed debugger messages to
the kernel.

Successful exploitation allows a malicious user to execute arbitrary
code on the vulnerable system with escalated privileges.

SOLUTION:
Apply patch via Windows Update or manually.

-- Windows NT 4.0 (with SP6a installed) --

All except Japanese NEC and Chinese - Hong Kong:
http://microsoft.com/downloads/details.aspx?FamilyId=C3596ED1-596F-416C-8BE5-91AE65619A1A&displaylang=en

Japanese NEC:
http://microsoft.com/downloads/details.aspx?FamilyId=6D83F8BA-BF16-4EC5-9187-9B03E9AE825F&displaylang=ja

Chinese - Hong Kong:
http://microsoft.com/downloads/details.aspx?FamilyId=0FF5C348-F7A0-44E8-8D82-557389FB4590&displaylang=zh-tw

-- Windows NT 4.0, Terminal Server Edition (with SP6 installed) --

All:
http://microsoft.com/downloads/details.aspx?FamilyId=910A0015-3723-4A4E-9049-99A4CE52B5F8&displaylang=en

-- Windows 2000 (any version with SP2/SP3 installed) --

All except Japanese NEC:
http://microsoft.com/downloads/details.aspx?FamilyId=CACAC8C0-81E9-413E-B565-5D7B3257A733&displaylang=en

Japanese NEC:
http://microsoft.com/downloads/details.aspx?FamilyId=81E6E80C-5E56-4466-98C1-4DDF6CF3893F&displaylang=ja

-- Windows XP --

32-bit Edition:
http://microsoft.com/downloads/details.aspx?FamilyId=9F81E615-3DEC-4A4B-826A-4E0FEAB42323&displaylang=en

64-bit Edition:
http://microsoft.com/downloads/details.aspx?FamilyId=DBC47904-51C8-475A-9900-3DF363A51A3A&displaylang=en

ORIGINAL ADVISORY:
http://microsoft.com/technet/security/bulletin/MS03-013.asp

OTHER REFERENCES:
http://www.kb.cert.org/vuls/id/446338

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------