Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.900740
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Windows Kernel Could Allow Elevation of Privilege (977165)
Resumen:This host is missing a critical security update according to; Microsoft Bulletin MS10-015.
Descripción:Summary:
This host is missing a critical security update according to
Microsoft Bulletin MS10-015.

Vulnerability Insight:
- Windows Kernel is not properly handling certain exceptions, which can be
exploited to execute arbitrary code with kernel privileges.

- Windows Kernel is not correctly resetting a pointer when freeing memory,
which can be exploited to trigger a double-free condition.

Vulnerability Impact:
Successful exploitation could allow attackers to execute arbitrary code with
kernel-level privilege.

Affected Software/OS:
- Microsoft Windows 7

- Microsoft Windows 2K Service Pack 4 and prior

- Microsoft Windows XP Service Pack 3 and prior

- Microsoft Windows 2K3 Service Pack 2 and prior

- Microsoft Windows Vista Service Pack 1/2 and prior

- Microsoft Windows Server 2008 Service Pack 1/2 and prior

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-0232
BugTraq ID: 37864
http://www.securityfocus.com/bid/37864
Bugtraq: 20100119 Microsoft Windows NT #GP Trap Handler Allows Users to Switch Kernel Stack (Google Search)
http://www.securityfocus.com/archive/1/509106/100/0/threaded
Cert/CC Advisory: TA10-040A
http://www.us-cert.gov/cas/techalerts/TA10-040A.html
http://seclists.org/fulldisclosure/2010/Jan/341
http://lock.cmpxchg8b.com/c0af0967d904cef2ad4db766a00bc6af/KiTrap0D.zip
http://lists.immunitysec.com/pipermail/dailydave/2010-January/006000.html
Microsoft Security Bulletin: MS10-015
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-015
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8344
http://securitytracker.com/id?1023471
http://secunia.com/advisories/38265
http://www.vupen.com/english/advisories/2010/0179
XForce ISS Database: ms-win-gptrap-privilege-escalation(55742)
https://exchange.xforce.ibmcloud.com/vulnerabilities/55742
Common Vulnerability Exposure (CVE) ID: CVE-2010-0233
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8392
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.