Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

New Windows CSRSS unpatched vulnerability

This new vulnerability is rated as low-risk can only be exploited by local users.

Microsoft Windows Client Server Run-Time Subsystem Memory Disclosure Vulnerability
http://www.frsirt.com/english/advisories/2006/5197
http://secunia.com/advisories/23491/

QUOTE: A Microsoft Windows vulnerability can be exploited by malicious local users to gain knowledge of sensitive information. The problem is that CSRSS.exe does not properly validate arguments passed via NtRaiseHardError and can be exploited to view the contents of CSRSS process memory. The vulnerability is confirmed on a fully-patched Windows XP SP2 system and reportedly affects Windows 2000 SP4 as well. Other versions may also be affected.

Solution: Allow only trusted users access to the system

Comments

Nimda said:

heh - niiice ...

if you're having a problem getting the forum to recognize a full link, surround it in

# June 3, 2007 9:59 PM