Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
BID:39320
Info
Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
| Bugtraq ID: | 39320 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-0482 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 13 2010 12:00AM |
| Updated: | Apr 14 2010 11:43PM |
| Credit: | Martin Tofall of Obsidium Software |
| Vulnerable: |
Microsoft Windows Server 2008 R2 Datacenter 0 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for Itanium-based Systems R2 Microsoft Windows Server 2008 R2 Microsoft Windows 7 XP Mode 0 Microsoft Windows 7 Ultimate 0 Microsoft Windows 7 Starter 0 Microsoft Windows 7 Professional 0 Microsoft Windows 7 Home Premium 0 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems 0 Microsoft Windows 7 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
Microsoft Windows is prone to a local denial-of-service vulnerability that affects the Windows kernel.
Attackers can exploit this issue to cause affected computers to become unresponsive and restart, causing a denial-of-service condition.
Microsoft Windows is prone to a local denial-of-service vulnerability that affects the Windows kernel.
Attackers can exploit this issue to cause affected computers to become unresponsive and restart, causing a denial-of-service condition.
Exploit / POC
Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows Server 2008 for Itanium-based Systems R2
Microsoft Windows Server 2008 for x64-based Systems R2
Microsoft Windows 7 for x64-based Systems 0
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Security Update for Windows 7 (KB979683)
http://www.microsoft.com/downloads/details.aspx?familyid=FF58D80C-33CE -4D9E-AAA5-0B1841458931
Microsoft Windows Server 2008 for Itanium-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB979683)
http://www.microsoft.com/downloads/details.aspx?familyid=D4EA3984-5183 -47F1-814E-29CB6C90AE06
Microsoft Windows Server 2008 for x64-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB979683)
http://www.microsoft.com/downloads/details.aspx?familyid=28389C1D-2A12 -4BEF-A59B-726BB6449C8B
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB979683)
http://www.microsoft.com/downloads/details.aspx?familyid=7F1DC055-2EC9 -407A-9E69-DA12338587E3
References
Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- ASA-2010-094 MS10-021 Vulnerabilities in Windows Kernel Could Allow Elevation of (Avaya)
- Microsoft Security Bulletin MS10-021 (Microsoft)