Microsoft Windows Registry Access Local Denial of Service Vulnerability
BID:18995
CVE-2006-3725 |Info
Microsoft Windows Registry Access Local Denial of Service Vulnerability
| Bugtraq ID: | 18995 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 15 2006 12:00AM |
| Updated: | Jul 04 2007 11:07PM |
| Credit: | Discovery is credited to David Matousek. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows XP 0 Microsoft Windows 2000 Professional |
| Not Vulnerable: | |
Discussion
Microsoft Windows Registry Access Local Denial of Service Vulnerability
Microsoft Windows is prone to a denial-of-service vulnerability.
This issue occurs when a program calls certain API calls for manipulating Windows registry keys. This may crash the affected computer.
NOTE: This BID has been revised (July 3, 2007); the issue was originally thought to be a vulnerability in Symantec Norton Personal Firewall, but further investigation reveals a problem in an underlying OS API.
Microsoft Windows is prone to a denial-of-service vulnerability.
This issue occurs when a program calls certain API calls for manipulating Windows registry keys. This may crash the affected computer.
NOTE: This BID has been revised (July 3, 2007); the issue was originally thought to be a vulnerability in Symantec Norton Personal Firewall, but further investigation reveals a problem in an underlying OS API.
Exploit / POC
Microsoft Windows Registry Access Local Denial of Service Vulnerability
The discoverer of this vulnerability has released an exploit (BTP00004P002NF.zip).
The zip contains the following files:
test.c
test.exe
readme.txt
Exercise caution with this exploit -- it will crash affected computers!
The discoverer of this vulnerability has released an exploit (BTP00004P002NF.zip).
The zip contains the following files:
test.c
test.exe
readme.txt
Exercise caution with this exploit -- it will crash affected computers!
Solution / Fix
Microsoft Windows Registry Access Local Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft Windows Registry Access Local Denial of Service Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft)