Microsoft Window Management API Local Privilege Escalation Vulnerability
BID:11378
Info
Microsoft Window Management API Local Privilege Escalation Vulnerability
| Bugtraq ID: | 11378 |
| Class: | Design Error |
| CVE: |
CVE-2004-0207 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 12 2004 12:00AM |
| Updated: | Dec 10 2008 10:51PM |
| Credit: | Discovery is credited to Brett Moore of Security-Assessment.com. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya IP600 Media Servers R9 Avaya IP600 Media Servers R8 Avaya IP600 Media Servers R7 Avaya IP600 Media Servers R6 Avaya IP600 Media Servers R12 Avaya IP600 Media Servers R11 Avaya IP600 Media Servers R10 Avaya IP600 Media Servers Avaya DefinityOne Media Servers R9 Avaya DefinityOne Media Servers R8 Avaya DefinityOne Media Servers R7 Avaya DefinityOne Media Servers R6 Avaya DefinityOne Media Servers R12 Avaya DefinityOne Media Servers R11 Avaya DefinityOne Media Servers R10 Avaya DefinityOne Media Servers |
| Not Vulnerable: |
Microsoft Windows XP Professional SP2 Microsoft Windows XP Home SP2 |
Discussion
Microsoft Window Management API Local Privilege Escalation Vulnerability
Microsoft has reported that several unspecified Window Management API functions can allow a local attacker to change the attributes of an application with higher-level privileges to gain elevated privileges on a vulnerable computer.
This issue represents a fundamental design flaw; certain messages used to communicate between windows on a desktop may adversely affect the operation of a receiving process. By altering various properties of window components running with higher privileges, the attacker can create circumstances that may allow buffer overflows and arbitrary code execution.
This issue likely affects some native Windows applications, but other third-party applications may also provide an opportunity for exploits.
Microsoft has reported that several unspecified Window Management API functions can allow a local attacker to change the attributes of an application with higher-level privileges to gain elevated privileges on a vulnerable computer.
This issue represents a fundamental design flaw; certain messages used to communicate between windows on a desktop may adversely affect the operation of a receiving process. By altering various properties of window components running with higher privileges, the attacker can create circumstances that may allow buffer overflows and arbitrary code execution.
This issue likely affects some native Windows applications, but other third-party applications may also provide an opportunity for exploits.
Exploit / POC
Microsoft Window Management API Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Window Management API Local Privilege Escalation Vulnerability
Solution:
Microsoft has released a bulletin that includes fixes to address this issue for supported versions of the operating system.
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows XP Professional
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows XP Home
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home SP1
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows 2000 Server SP3
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows XP Professional SP1
Solution:
Microsoft has released a bulletin that includes fixes to address this issue for supported versions of the operating system.
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=533AE5CD-74CE -470A-8916-8E358084497C&displaylang=en
Microsoft Windows NT Terminal Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=533AE5CD-74CE -470A-8916-8E358084497C&displaylang=en
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Security Update for Windows NT Server 4.0, Terminal Server Edition (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=3B871A96-5F64 -4432-920F-FA5760DF683A&displaylang=en
Microsoft Windows XP Professional
-
Microsoft Security Update for Windows XP (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=715E985B-7929 -4BD5-9564-5CFE7D528398&displaylang=en
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=533AE5CD-74CE -470A-8916-8E358084497C&displaylang=en
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft Security Update for Windows XP 64-bit Edition (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=99184841-70A8 -47C7-9993-44A60E999A40&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows 2000 Professional SP3
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows XP Home
-
Microsoft Security Update for Windows XP (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=715E985B-7929 -4BD5-9564-5CFE7D528398&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=715E985B-7929 -4BD5-9564-5CFE7D528398&displaylang=en
Microsoft Windows 2000 Datacenter Server SP3
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows XP 64-bit Edition Version 2003
-
Microsoft Security Update for Windows Server 2003 64-Bit and Windows XP 64-Bit Version 2003 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=B4E6BBCF-F5B9 -4B2D-8BC4-30911CA4FD9C&displaylang=en
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=533AE5CD-74CE -470A-8916-8E358084497C&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=4A614222-BA0B -4927-856D-D443BBBE1A42&displaylang=en
Microsoft Windows XP Professional SP1
-
Microsoft Security Update for Windows XP (KB840987)
http://www.microsoft.com/downloads/details.aspx?familyid=715E985B-7929 -4BD5-9564-5CFE7D528398&displaylang=en
References
Microsoft Window Management API Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-032 (Microsoft)
- SetWindowLong Shatter Attacks ("Brett Moore"
)