Windows TCP/IP Stack Lets Remote Users Bypass the Firewall and Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1027044 |
|
SecurityTracker URL: http://securitytracker.com/id/1027044
|
|
CVE Reference:
CVE-2012-0174, CVE-2012-0179
(Links to External Site)
|
Date: May 8 2012
|
Impact:
Host/resource access via network, User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): Vista SP2, 7 SP1, 2008 SP2, 2008 R2 SP1; and prior service packs
|
Description:
Two vulnerabilities were reported in the Windows TCP/IP Stack. A local user can obtain elevated privileges on the target system. A remote user on the local network can bypass the firewall in certain cases.
In certain cases, Windows Firewall does not properly filter outbound broadcast packets with an outbound firewall rule applied [CVE-2012-0174]. A remote user on the local network can bypass the firewall. Bojan Zdrnja of INFIGO IS reported this vulnerability.
The TCP/IP stack does not properly handle the binding of an IPv6 address to a local interface [CVE-2012-0179]. A local user can exploit this to trigger a double free memory error and execute arbitrary commands on the target system with elevated privileges.
|
Impact:
A local user can obtain elevated privileges on the target system.
A remote user on the local network can bypass the firewall in certain cases.
|
Solution:
The vendor has issued the following fixes:
Windows Vista Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=b1dc6e10-34eb-45ea-92b3-9983c00f6cb5
Windows Vista x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=d65565d4-d865-438a-bfb7-d71af9dd884e
Windows Server 2008 for 32-bit Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=7ef72aab-7fd2-4330-bb6a-0c77c3943345
Windows Server 2008 for x64-based Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=9569d980-766d-4825-bd1c-f30c93d4b035
Windows Server 2008 for Itanium-based Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=c5f7ee25-2fc1-44c7-b3e6-e2c969ecf1bc
Windows 7 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=46b8749e-3d8f-472f-a1ea-419f44c6bc00
Windows 7 for 32-bit Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=46b8749e-3d8f-472f-a1ea-419f44c6bc00
Windows 7 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=e89fb3f1-44cb-4fc0-bbc2-8e94d6933322
Windows 7 for x64-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=e89fb3f1-44cb-4fc0-bbc2-8e94d6933322
Windows Server 2008 R2 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=08ba4320-6c47-4f82-a54f-61a32629b985
Windows Server 2008 R2 for x64-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=08ba4320-6c47-4f82-a54f-61a32629b985
Windows Server 2008 R2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=34643abe-2905-4ac1-a5f3-3f6ea8724b7a
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=34643abe-2905-4ac1-a5f3-3f6ea8724b7a
Windows Server 2008 for 32-bit Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=7ef72aab-7fd2-4330-bb6a-0c77c3943345
Windows Server 2008 for x64-based Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=9569d980-766d-4825-bd1c-f30c93d4b035
Windows Server 2008 R2 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=08ba4320-6c47-4f82-a54f-61a32629b985
Windows Server 2008 R2 for x64-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=08ba4320-6c47-4f82-a54f-61a32629b985
A restart is required.
The Microsoft advisory is available at:
http://technet.microsoft.com/en-us/security/bulletin/ms12-032
|
Vendor URL: technet.microsoft.com/en-us/security/bulletin/ms12-032 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|