Microsoft Windows 'NtUserCheckAccessForIntegrityLevel' Local Privilege Escalation Vulnerability
BID:41280
Info
Microsoft Windows 'NtUserCheckAccessForIntegrityLevel' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 41280 |
| Class: | Unknown |
| CVE: |
CVE-2010-2549 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 01 2010 12:00AM |
| Updated: | Oct 15 2010 03:59PM |
| Credit: | Microsoft-Spurned Researcher Collective |
| Vulnerable: |
Microsoft Windows Vista Ultimate 64-bit edition SP2 Microsoft Windows Vista Ultimate 64-bit edition SP1 Microsoft Windows Vista Home Premium 64-bit edition SP2 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition SP2 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition SP2 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Business 64-bit edition SP2 Microsoft Windows Vista Business 64-bit edition SP1 Microsoft Windows Vista Ultimate SP2 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista Home Premium SP2 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Basic SP2 Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Enterprise SP2 Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Business SP2 Microsoft Windows Vista Business SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 0 Avaya Aura Conferencing Standard Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows 'NtUserCheckAccessForIntegrityLevel' Local Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel.
An attacker may exploit this issue to execute arbitrary code with kernel-level privileges, however, this has not been confirmed. Successful exploits will result in the complete compromise of affected computers. Failed exploit attempts may cause a denial-of-service condition.
Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel.
An attacker may exploit this issue to execute arbitrary code with kernel-level privileges, however, this has not been confirmed. Successful exploits will result in the complete compromise of affected computers. Failed exploit attempts may cause a denial-of-service condition.
Exploit / POC
Microsoft Windows 'NtUserCheckAccessForIntegrityLevel' Local Privilege Escalation Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
Microsoft Windows 'NtUserCheckAccessForIntegrityLevel' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the referenced advisory for more information.
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for Itanium-based Systems 0
Solution:
Updates are available. Please see the referenced advisory for more information.
Microsoft Windows Server 2008 for Itanium-based Systems SP2
-
Microsoft Windows6.0-KB981957-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=B9096046-8C7A -450C-B8C5-6E9FB001E6CD
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Windows6.0-KB981957-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=B9096046-8C7A -450C-B8C5-6E9FB001E6CD
References
Microsoft Windows 'NtUserCheckAccessForIntegrityLevel' Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft )
- MS10-073 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of (Avaya)
- MSRC-001: Windows Vista/Server 2008 NtUserCheckAccessForIntegrityLevel Use-after (Microsoft-Spurned Researcher Collective)
- Microsoft Security Bulletin MS10-073 (Microsoft)