Windows Kernel GDI Input Validation Flaw in Processing Application Size Parameters Lets Local Users Gain System Privileges
|
|
SecurityTracker Alert ID: 1017846 |
|
SecurityTracker URL: http://securitytracker.com/id/1017846
|
|
CVE Reference:
CVE-2006-5586
(Links to External Site)
|
Updated: Apr 6 2007
|
Original Entry Date: Apr 3 2007
|
Impact:
Execution of arbitrary code via local system, Root access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2000 SP4, XP SP2; and prior service packs
|
Description:
A vulnerability was reported in the Windows Kernel. A local user can obtain system privileges on the target system.
The Microsoft Windows graphics device interface (GDI) interface does not properly validate user-supplied input. A local user can invoke the interface to execute arbitrary commands on the target system with System privileges.
A specially crafted application window size parameter can trigger the vulnerability.
|
Impact:
A local user can obtain System privileges on the target system.
|
Solution:
The vendor has issued the following fixes:
Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=92F20599-3E7B-4217-91E6-FDCFB4C56856
Microsoft Windows XP Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=F82EA184-945F-4B78-9463-10AC20A75020
Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EA5E1B87-4DB5-4B1A-891E-29C6BD6C0184
A restart is required.
The MS07-017 patch may cause some third-party applications to fail to start on Windows XP. A hotfix is available for this problem, as described in the following knowledge base article:
http://support.microsoft.com/kb/935448/
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms07-017.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms07-017.mspx (Links to External Site)
|
Cause:
Input validation error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 3 Apr 2007 13:15:19 -0400
Subject: Microsoft Security Bulletin MS07-017: Vulnerabilities in GDI Could Allow Remote Code Execution (925902)
|
http://www.microsoft.com/technet/security/bulletin/ms07-017.mspx
CVE-2007-0038
CVE-2006-5758
CVE-2006-5586
CVE-2007-1211
CVE-2007-1212
CVE-2007-1215
CVE-2007-1213
|
|