Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-04-03.1

iDefense Security Advisory 04.03.07 – Remote exploitation of a design error in certain kernel GDI functions in multiple versions of Microsoft Corp.’s Windows operating system may allow an attacker to cause a denial of service condition. During testing of the MS06-001 WMF (Windows Metafile) vulnerability, a flaw was found in the handling of WMF files. This flaw can cause the kernel to perform a bug check, also known as a “blue screen” or system crash, when it tries to parse the file. The cause of this bug check is an attempt by a function in a kernel system call to read a value obtained by dereferencing an offset into a kernel structure. This value had been previously created and then reset by previous system calls, and at the point it is accessed it does not contain a valid memory reference. This results in an access violation error, which in turn triggers the bug check. This vulnerability is different from both the Microsoft MS06-001 WMF vulnerability and the MS05-053 WMF vulnerability and is not fixed by either of these patches.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55584/04.03.07-1.txt

Source: https://packetstormsecurity.com/files/55584/iDEFENSE-Security-Advisory-2007-04-03.1.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534