Microsoft Windows Kernel Virtual DOS Machine特权提升漏洞

漏洞信息详情

Microsoft Windows Kernel Virtual DOS Machine特权提升漏洞

漏洞简介

Microsoft Windows NT 4.0版本,Windows 2000版本,Windows XP版本和Windows Server 2003版本的Virtual DOS Machine (VDM)子系统存在漏洞。本地用户可以借助恶意程序进入核心内存以及提升特权,该恶意程序以一种通过授予操作系统函数特权来不恰当验证的方式修改一些系统结构。

漏洞公告

Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Customers are advised to follow Microsoft’s guidance for applying patches. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=203487&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft has released a bulletin that includes fixes to address this issue for supported versions of the operating system.
Microsoft Windows NT Server 4.0 SP6a

Microsoft Windows NT Terminal Server 4.0 SP6a

Microsoft Windows NT Terminal Server 4.0 SP6

Microsoft Windows XP Professional

Microsoft Windows NT Workstation 4.0 SP6a

Microsoft Windows XP 64-bit Edition SP1

Microsoft Windows 2000 Advanced Server SP4

Microsoft Windows 2000 Professional SP3

Microsoft Windows 2000 Datacenter Server SP4

Microsoft Windows XP Home

Microsoft Windows 2000 Advanced Server SP3

Microsoft Windows XP Home SP1

Microsoft Windows 2000 Datacenter Server SP3

Microsoft Windows 2000 Server SP3

Microsoft Windows XP 64-bit Edition Version 2003

Microsoft Windows NT Enterprise Server 4.0 SP6a

Microsoft Windows 2000 Server SP4

Microsoft Windows 2000 Professional SP4

Microsoft Windows XP Professional SP1

参考网址

来源:US-CERT Vulnerability Note: VU#910998
名称: VU#910998
链接:http://www.kb.cert.org/vuls/id/910998

来源: XF
名称: win-ms04032-patch(17658)
链接:http://xforce.iss.net/xforce/xfdb/17658

来源: XF
名称: win-vdm-gain-privilege(16580)
链接:http://xforce.iss.net/xforce/xfdb/16580

来源: MS
名称: MS04-032
链接:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp

来源: BUGTRAQ
名称: 20041013 EEYE: Windows VDM #UD Local Privilege Escalation
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109772135404427&w=2

来源: US Government Resource: oval:org.mitre.oval:def:4762
名称: oval:org.mitre.oval:def:4762
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762

来源: US Government Resource: oval:org.mitre.oval:def:4316
名称: oval:org.mitre.oval:def:4316
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316

来源: US Government Resource: oval:org.mitre.oval:def:3953
名称: oval:org.mitre.oval:def:3953
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953

来源: US Government Resource: oval:org.mitre.oval:def:3161
名称: oval:org.mitre.oval:def:3161
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161

来源: US Government Resource: oval:org.mitre.oval:def:1751
名称: oval:org.mitre.oval:def:1751
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享