Microsoft Windows Manifest File Privilege Escalation Vulnerability
BID:21550
Info
Microsoft Windows Manifest File Privilege Escalation Vulnerability
| Bugtraq ID: | 21550 |
| Class: | Design Error |
| CVE: |
CVE-2006-5585 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 12 2006 12:00AM |
| Updated: | Dec 12 2006 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 0 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Manifest File Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability because the software fails to properly process and manage file manifests.
An attacker may exploit this issue to manipulate file manifests to elevate user privileges. Successful exploits will result in the complete compromise of vulnerable computers.
Microsoft Windows is prone to a local privilege-escalation vulnerability because the software fails to properly process and manage file manifests.
An attacker may exploit this issue to manipulate file manifests to elevate user privileges. Successful exploits will result in the complete compromise of vulnerable computers.
Exploit / POC
Microsoft Windows Manifest File Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution / Fix
Microsoft Windows Manifest File Privilege Escalation Vulnerability
Solution:
Microsoft has released a security bulletin and fixes to address this issue. Please see the referenced security bulletin for details.
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows Server 2003 Web Edition
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows XP Professional SP2
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows XP Home SP2
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Solution:
Microsoft has released a security bulletin and fixes to address this issue. Please see the referenced security bulletin for details.
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft WindowsXP-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=966704b5-1a7e -4110-9694-844706a52db7&displaylang=en
Microsoft Windows Server 2003 Web Edition
-
Microsoft WindowsServer2003-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=5ea314a2-d76a -46f9-853b-15ff03f8ad95&displaylang=en
Microsoft Windows XP Media Center Edition SP2
-
Microsoft WindowsXP-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=966704b5-1a7e -4110-9694-844706a52db7&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft WindowsServer2003-KB926255-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=7bceaa11-f655 -4e3c-a588-5c49097e970b&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft WindowsServer2003-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=5ea314a2-d76a -46f9-853b-15ff03f8ad95&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft WindowsServer2003-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=5ea314a2-d76a -46f9-853b-15ff03f8ad95&displaylang=en
Microsoft Windows XP Professional SP2
-
Microsoft WindowsXP-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=966704b5-1a7e -4110-9694-844706a52db7&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft WindowsServer2003-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=5ea314a2-d76a -46f9-853b-15ff03f8ad95&displaylang=en
Microsoft Windows XP Home SP2
-
Microsoft WindowsXP-KB926255-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=966704b5-1a7e -4110-9694-844706a52db7&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft WindowsServer2003-KB926255-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=7bceaa11-f655 -4e3c-a588-5c49097e970b&displaylang=en
References
Microsoft Windows Manifest File Privilege Escalation Vulnerability
References:
References:
- ASA-2006-277 - MS06-075 Vulnerability in Windows Could Allow Elevation of Privil (Avaya)
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS06-075 (Microsoft)