Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   


Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker

Category:   Application (Generic)  >   Microsoft Virtual PC/Server Vendors:   Microsoft
Microsoft Virtual PC/Server Heap Overflow Lets Local Users Gain Elevated Privileges
SecurityTracker Alert ID:  1018567
SecurityTracker URL:
CVE Reference:   CVE-2007-0948   (Links to External Site)
Updated:  Nov 14 2007
Original Entry Date:  Aug 14 2007
Impact:   User access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 2004, 2004 SP1, 2005, 2005 R2; 6.1 for Mac, 7 for Mac
Description:   A vulnerability was reported in Microsoft Virtual PC and Microsoft Virtual Server. A local user can obtain elevated privileges on the target system.

A local user with administrator permissions on the the guest operating system can trigger a heap overflow and execute arbitrary code on the target host system or other guest operating systems.

Microsoft Virtual Server 2005 R2 SP1 and Microsoft Virtual PC 2007 are not affected.

Rafal Wojtczuk of McAfee Avert Labs reported this vulnerability.

Impact:   A local user can obtain elevated privileges on the target system.
Solution:   On August 14, 2007, Microsoft issued a fix. However, this original fix did not apply properly on some systems.

On November 13, 2007, Microsoft re-issued the fix. The new fix does not need to be applied on systems where the original update was successful.

The vendor has issued the following revised fixes:

Microsoft Virtual PC 2004:

Microsoft Virtual PC 2004 Service Pack 1:

Microsoft Virtual Server 2005 Standard Edition:

Microsoft Virtual Server 2005 Enterprise Edition:

Microsoft Virtual Server 2005 R2 Standard Edition:

Microsoft Virtual Server 2005 R2 Enterprise Edition:

Microsoft Virtual PC for Mac Version 6.1, Microsoft Virtual PC for Mac Version 7:

A restart is required.

The Microsoft advisory is available at:

Vendor URL: (Links to External Site)
Cause:   Boundary error
Underlying OS:  UNIX (OS X), Windows (Any)

Message History:   None.

 Source Message Contents

[Original Message Not Available for Viewing]

Go to the Top of This SecurityTracker Archive Page

Home   |    View Topics   |    Search   |    Contact Us

Copyright 2015, LLC