Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
BID:43779
Info
Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
| Bugtraq ID: | 43779 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2741 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 12 2010 12:00AM |
| Updated: | Oct 18 2010 03:59PM |
| Credit: | Diego Juarez of Core Security Technologies |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP3 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional SP3 Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Home SP3 Microsoft Windows XP Embedded SP3 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 0 3DM Software Disk Management Software Sp2 Storage 3DM Software Disk Management Software Sp2 Enterprise 3DM Software Disk Management Software Sp2 Datacenter 3DM Software Disk Management Software Sp2 Compute Cluster 3DM Software Disk Management Software SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability.
Attackers may exploit this issue to execute arbitrary code with kernel-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Windows is prone to a local privilege-escalation vulnerability.
Attackers may exploit this issue to execute arbitrary code with kernel-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows XP Media Center Edition SP3
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows XP Home SP3
Microsoft Windows XP Professional x64 Edition SP2
3DM Software Disk Management Software SP2
Microsoft Windows XP Tablet PC Edition SP3
Microsoft Windows Server 2003 Standard Edition SP2
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft WindowsServer2003-KB2279986-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=E8F297E2-0DFD -421A-B598-A78199AD6BAA
Microsoft Windows XP Media Center Edition SP3
-
Microsoft WindowsXP-KB2279986-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=0553FC7C-DEED -4594-A133-D621551310DC
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft WindowsServer2003-KB2279986-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=F94763E7-B1DB -4043-AA79-D5BE1A42307D
Microsoft Windows XP Home SP3
-
Microsoft WindowsXP-KB2279986-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=0553FC7C-DEED -4594-A133-D621551310DC
Microsoft Windows XP Professional x64 Edition SP2
-
Microsoft WindowsServer2003.WindowsXP-KB2279986-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=1AD30596-BAC6 -4D48-8B15-0245960C443B
3DM Software Disk Management Software SP2
-
Microsoft WindowsServer2003-KB2279986-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=F94763E7-B1DB -4043-AA79-D5BE1A42307D
Microsoft Windows XP Tablet PC Edition SP3
-
Microsoft WindowsXP-KB2279986-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=0553FC7C-DEED -4594-A133-D621551310DC
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft WindowsServer2003-KB2279986-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=F94763E7-B1DB -4043-AA79-D5BE1A42307D
References
Microsoft Windows OpenType Font (OTF) Format Driver CVE-2010-2741 Privilege Escalation Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft )
- [CORE-2010-0624] MS OpenType CFF Parsing Vulnerability ([email protected])
- ASA-2010-283 (Avaya)
- Microsoft Security Bulletin MS10-078 (Microsoft)