Microsoft Windows Tracing Registry Key ACL Privilege Escalation Vulnerability
BID:42269
Info
Microsoft Windows Tracing Registry Key ACL Privilege Escalation Vulnerability
| Bugtraq ID: | 42269 |
| Class: | Design Error |
| CVE: |
CVE-2010-2554 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 10 2010 12:00AM |
| Updated: | Aug 11 2010 08:34PM |
| Credit: | Cesar Cerrudo of Argeniss |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista Ultimate 64-bit edition SP2 Microsoft Windows Vista Ultimate 64-bit edition SP1 Microsoft Windows Vista Home Premium 64-bit edition SP2 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition SP2 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition SP2 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Business 64-bit edition SP2 Microsoft Windows Vista Business 64-bit edition SP1 Microsoft Windows Vista Ultimate SP2 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista SP2 Microsoft Windows Vista SP1 Microsoft Windows Vista Home Premium SP2 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Basic SP2 Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Enterprise SP2 Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Business SP2 Microsoft Windows Vista Business SP1 Microsoft Windows Server 2008 Standard Edition X64 Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems R2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows 7 Ultimate 0 Microsoft Windows 7 Starter 0 Microsoft Windows 7 Professional 0 Microsoft Windows 7 Home Premium 0 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for Itanium-based Systems 0 Microsoft Windows 7 for 32-bit Systems 0 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows Tracing Registry Key ACL Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will result in the complete compromise of affected computers.
Microsoft Windows is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will result in the complete compromise of affected computers.
Exploit / POC
Microsoft Windows Tracing Registry Key ACL Privilege Escalation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Microsoft Windows Tracing Registry Key ACL Privilege Escalation Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows Vista SP1
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2008 for x64-based Systems R2
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Vista SP2
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows Server 2008 for Itanium-based Systems R2
Microsoft Windows Vista x64 Edition SP2
Microsoft Windows Server 2008 for Itanium-based Systems 0
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Vista x64 Edition SP1
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows Vista SP1
-
Microsoft Security Update for Windows Vista (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=DFB31AA2-7457 -4581-9E28-7984A360EDF4
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=FA84E547-2190 -402F-9467-2450DEEFF565
Microsoft Windows Server 2008 for Itanium-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=84F89DCA-108C -4956-9AA2-866E17A872FC
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9B3E60-E166 -40C9-8938-3CBA0A399C47
Microsoft Windows Server 2008 for x64-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=333FB6E4-F867 -4DCB-BEB3-2D88E428CA2E
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=146270FA-CD6F -440A-AA3E-E93AF0BFF447
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=FA84E547-2190 -402F-9467-2450DEEFF565
Microsoft Windows Vista SP2
-
Microsoft Security Update for Windows Vista (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=DFB31AA2-7457 -4581-9E28-7984A360EDF4
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Security Update for Windows 7 (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=CE6233F3-2EE5 -4329-908D-BA9B28ECC553
Microsoft Windows Server 2008 for Itanium-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=62034ECB-A6BD -46C5-A03D-9642880BC2D6
Microsoft Windows Vista x64 Edition SP2
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=110F932F-D13C -4486-A295-E6068D5D8D7A
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=84F89DCA-108C -4956-9AA2-866E17A872FC
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2008 (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=4C9B3E60-E166 -40C9-8938-3CBA0A399C47
Microsoft Windows Vista x64 Edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB982799)
http://www.microsoft.com/downloads/details.aspx?familyid=110F932F-D13C -4486-A295-E6068D5D8D7A
References
Microsoft Windows Tracing Registry Key ACL Privilege Escalation Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Windows weak registry permissions vulnerability (Cesar Cerrudo)
- ASA-2010-215 MS10-059 Vulnerabilities in the Tracing Feature for Services (Avaya)
- Microsoft Security Bulletin MS10-059 (Microsoft)