Microsoft Windows LSASS Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1019165
|
|
SecurityTracker URL: http://securitytracker.com/id?1019165
|
|
CVE Reference: CVE-2007-5352
(Links to External Site)
|
Date: Jan 8 2008
|
Impact: Execution of arbitrary code via local system, Root access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Bulletin
|
Version(s): 2000 SP4, 2003 SP2, XP SP2; and prior service packs
|
Description: A vulnerability was reported in Microsoft Windows in the Local Security Authority Subsystem Service (LSASS). A local user can obtain elevated privileges on the target system.
The LSASS service does not properly handle local procedure call (LPC) requests. A local user can send a specially crafted LPC request
to execute arbitrary code on the target system with system level privileges.
Windows Vista is not affected.
Thomas Garnier
of SkyRecon reported this vulnerability.
|
Impact: A local user can obtain system privileges on the target system.
|
Solution: The vendor has issued the following fixes:
Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7956632e-17d9-4876-8340-84
fe3e43e5cc
Windows XP Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=6a4cf182-8e36-490e-aefe-edb7b3a0df9c
Windows
XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyID=51fc657b-2b4a-4725-a744-d2
79e027c4a5
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyID=12397b47-b18f-4d4d-b8
d7-adec8ff310d5
Windows Server 2003 x64 Edition and Windows 2003 Server x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyID=f19fd79
0-a4e6-4a8a-8077-d1bbfe37ecca
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium
based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyID=0382a195-aa3d-409b-8a79-9fe61588d8a9
A restart is
required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-002.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-002.mspx (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 8 Jan 2008 13:17:26 -0500
Subject: Microsoft Security Bulletin MS08-002 Important: Vulnerability in LSASS Could Allow Local Elevation of Privilege (943485)
|
http://www.microsoft.com/technet/security/bulletin/ms08-002.mspx
CVE-2007-5352
|
|