Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability
BID:26121
Info
Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability
| Bugtraq ID: | 26121 |
| Class: | Design Error |
| CVE: |
CVE-2007-5587 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 18 2007 12:00AM |
| Updated: | Dec 19 2007 02:11PM |
| Credit: | Elia Florio of Symantec found this issue being exploited in the wild. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Home SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Macrovision Safedisc 0 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability
Macrovision SafeDisc is prone to a local privilege-escalation vulnerability because it fails to adequately sanitize user-supplied input.
Exploiting this vulnerability allows local attackers to execute arbitrary malicious code with SYSTEM-level privileges, facilitating the complete compromise of affected computers.
UPDATE: This issue affects only Microsoft Windows XP and 2003 platforms. Microsoft Vista is not affected.
Macrovision SafeDisc is prone to a local privilege-escalation vulnerability because it fails to adequately sanitize user-supplied input.
Exploiting this vulnerability allows local attackers to execute arbitrary malicious code with SYSTEM-level privileges, facilitating the complete compromise of affected computers.
UPDATE: This issue affects only Microsoft Windows XP and 2003 platforms. Microsoft Vista is not affected.
Exploit / POC
Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product:
http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1991
NOTE: This issue is being exploited in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product:
http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1991
NOTE: This issue is being exploited in the wild.
The following exploit is available:
Solution / Fix
Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
Microsoft released a security bulletin to provide updates for supported versions of Microsoft Windows XP and Server 2003. This bulletin provides the same fixes offered by Macrovision. Please see the references for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows Server 2003 Datacenter x64 Edition
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Web Edition SP1
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2003 Standard Edition SP1
Macrovision Safedisc 0
Microsoft Windows Server 2003 SP2
Microsoft Windows XP Professional SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Standard x64 Edition
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows XP Home SP2
Microsoft Windows Server 2003 SP1
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
Microsoft released a security bulletin to provide updates for supported versions of Microsoft Windows XP and Server 2003. This bulletin provides the same fixes offered by Macrovision. Please see the references for more information.
Microsoft Windows Server 2003 Datacenter Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Microsoft Windows Server 2003 Datacenter x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=1f416b71-783f -4cbc-9b85-9a9be7daa0d7&displaylang=en
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft Security Update for Windows XP (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=c7d368d0-f7bf -4946-a4a6-3e88315e5317&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Microsoft Windows XP Media Center Edition SP2
-
Microsoft Security Update for Windows XP (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=c7d368d0-f7bf -4946-a4a6-3e88315e5317&displaylang=en
Microsoft Windows XP Professional x64 Edition
-
Microsoft Security Update for Windows XP x64 Edition (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=5f4fa8e9-fcf2 -4daf-93c0-8bb267da69aa&displaylang=en
Microsoft Windows Server 2003 Web Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Microsoft Windows Server 2003 Standard Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Macrovision Safedisc 0
-
Macrovision SECDRVSYS.zip
http://www.macrovision.com/webdocuments/Downloads/SECDRVSYS.zip
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Microsoft Windows XP Professional SP2
-
Microsoft Security Update for Windows XP (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=c7d368d0-f7bf -4946-a4a6-3e88315e5317&displaylang=en
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=1f416b71-783f -4cbc-9b85-9a9be7daa0d7&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=5f4fa8e9-fcf2 -4daf-93c0-8bb267da69aa&displaylang=en
Microsoft Windows Server 2003 Standard x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=1f416b71-783f -4cbc-9b85-9a9be7daa0d7&displaylang=en
Microsoft Windows Server 2003 Enterprise x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=1f416b71-783f -4cbc-9b85-9a9be7daa0d7&displaylang=en
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
Microsoft Windows XP Home SP2
-
Microsoft Security Update for Windows XP (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=c7d368d0-f7bf -4946-a4a6-3e88315e5317&displaylang=en
Microsoft Windows Server 2003 SP1
-
Microsoft Security Update for Windows Server 2003 (KB944653)
http://www.microsoft.com/downloads/details.aspx?FamilyID=0f84f5e2-1dd8 -4882-b796-444ab70b6b02&displaylang=en
References
Macrovision SafeDisc SecDRV.SYS Method_Neither Local Privilege Escalation Vulnerability
References:
References:
- ASA-2007-511 - MS07-067 Vulnerability in Macrovision Driver Could Allow Local El (Avaya)
- Privilege Escalation Exploit In the Wild (Symantec)
- Safedisc Web SIte (Macrovision)
- Symantec warns of local privilege escalation 0Day in Windows. Busted. (Reverse Mode)
- [CORRECTED] Microsoft Windows XP SP2/2003 - Macrovision (Reversemode
) - Microsoft Windows XP/2003 Macrovision SecDrv.sys privilege escalation (0day) (Reversemode
) - Microsoft Security Advisory (944653) Vulnerability in Macrovision SECDRV.SYS Dri (Microsoft)
- Microsoft Security Bulletin MS07-067 (Microsoft)