Affected Versions:
Microsoft Windows Vista SP2Microsoft Windows Vista SP1Microsoft Windows Server 2008 SP2Microsoft Windows Server 2008
Vulnerability description:
Microsoft Windows is a very popular operating system released by Microsoft. The Windows Kernel does not properly initialize objects when handling certain errors, which may cause double release.
Local users can gain kernel-level permission improvement by running malicious applications.
Attackers can exploit this vulnerability to execute arbitrary kernel code. Attackers can then install programs to view, change, or delete data;
Or create a new account with full user permissions.
<* Reference
Tavis Ormandy (
Taviso@gentoo.org)
Http://secunia.com/advisories/40871/
Http://www.microsoft.com/technet/security/bulletin/MS10-047.mspx? Pf = true
Http://www.us-cert.gov/cas/techalerts/TA10-222A.html
*>
Vendor patch: Microsoft --------- Microsoft has released a Security Bulletin (MS10-047) and patch: MS10-047: Vulnerabilities in Windows Kernel cocould Allow Elevation of Privilege
(981852) Link: http://www.microsoft.com/technet/security/bulletin/MS10-047.mspx? Pf = true