int(2999)

Vulnerability Bulletins


Aumento de privilegios al detectar hardware en Windows

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 / Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 / Itanium-based Systems
Microsoft Windows Server 2003 SP1 / Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition

Description

Se ha descubierto una vulnerabilidad en Microsoft Windows XP SP2 y Profesional, y en Server 2003 SP1. La vulnerabilidad reside en un error en la funcionalidad de detección de hardware en el intérprete de comandos de Windows.

Un atacante local podría ganar privilegios mediante un parámetro no válido en una función relacionada con la detección y registro de nuevo hardware.

Solution



Actualización de software

Microsoft
Microsoft Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=f821b3a0-4e5a-4737-b9bf-1249f6683f4d
Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=75abff9b-c2b5-4151-b366-4be652882944
Microsoft Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=418acc52-0ebd-4623-81a7-5eacc21c3965
Microsoft Windows Server 2003 Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=418acc52-0ebd-4623-81a7-5eacc21c3965
Microsoft Windows Server 2003 / Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyId=dc33a2fc-2d01-4577-b133-017493d1f278
Microsoft Windows Server 2003 SP1 / Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyId=dc33a2fc-2d01-4577-b133-017493d1f278
Microsoft Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=c3e55066-b34e-485d-ac04-179f8e3a407a

Standar resources

Property Value
CVE CVE-2007-0211
BID 22481

Other resources

Microsoft Security Bulletin MS07-006
http://www.microsoft.com/technet/security/bulletin/ms07-006.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2007-02-16
Ministerio de Defensa
CNI
CCN
CCN-CERT