Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
BID:50510
Info
Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
| Bugtraq ID: | 50510 |
| Class: | Design Error |
| CVE: |
CVE-2011-2004 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2011 12:00AM |
| Updated: | Nov 15 2011 12:51AM |
| Credit: | Will Dorman of the CERT/CC |
| Vulnerable: |
Microsoft Windows Server 2008 Standard Edition R2 SP1 Microsoft Windows Server 2008 Standard Edition R2 Microsoft Windows Server 2008 R2 x64 SP1 Microsoft Windows Server 2008 R2 x64 0 Microsoft Windows Server 2008 R2 Standard Edition 0 Microsoft Windows Server 2008 R2 Itanium SP1 Microsoft Windows Server 2008 R2 Itanium 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 0 Microsoft Windows Server 2008 R2 Microsoft Windows 7 Home Premium 0 Microsoft Windows 7 Home Premium - Sp1 X64 Microsoft Windows 7 Home Premium - Sp1 X32 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for 32-bit Systems 0 Microsoft Windows 7 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
Microsoft Windows is prone to a remote denial-of-service vulnerability that occurs in the Windows kernel 'Win32k.sys' kernel-mode device driver.
A remote attacker can exploit this issue to crash the Windows kernel, denying service to legitimate users.
Microsoft Windows is prone to a remote denial-of-service vulnerability that occurs in the Windows kernel 'Win32k.sys' kernel-mode device driver.
A remote attacker can exploit this issue to crash the Windows kernel, denying service to legitimate users.
Exploit / POC
Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft Windows Server 2008 R2 Itanium SP1
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows Server 2008 R2 for x64-based Systems SP1 0
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows Server 2008 R2 x64 SP1
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Server 2008 R2 Itanium 0
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft Windows Server 2008 R2 Itanium SP1
-
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=395819e2-1028 -44b7-ace4-ca754b1a7543
Microsoft Windows 7 for 32-bit Systems SP1
-
Microsoft Security Update for Windows 7 (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=156c1bd9-55bc -482c-874b-61998d1ef153
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Security Update for Windows 7 (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=156c1bd9-55bc -482c-874b-61998d1ef153
Microsoft Windows Server 2008 R2 for x64-based Systems SP1 0
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=5d810dae-5c52 -4155-b5c2-163d27be6e78
Microsoft Windows 7 for x64-based Systems SP1
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=5c7db930-5495 -43f0-928c-d586ac9e80d0
Microsoft Windows Server 2008 R2 x64 SP1
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=5d810dae-5c52 -4155-b5c2-163d27be6e78
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=5c7db930-5495 -43f0-928c-d586ac9e80d0
Microsoft Windows Server 2008 R2 Itanium 0
-
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB2617657)
http://www.microsoft.com/downloads/details.aspx?familyid=395819e2-1028 -44b7-ace4-ca754b1a7543
References
Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- ASA-2011-344 MS11-084 Vulnerability in Windows Kernel-Mode Drivers Could Allow D (Avaya)
- Microsoft Security Bulletin MS11-084 (Microsoft)