Microsoft Windows Ancillary Function Driver CVE-2012-0149 Local Privilege Escalation Vulnerability
BID:51936
Info
Microsoft Windows Ancillary Function Driver CVE-2012-0149 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 51936 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0149 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 14 2012 12:00AM |
| Updated: | Mar 02 2012 07:00PM |
| Credit: | Tarjei Mandt of Azimuth Security |
| Vulnerable: |
Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Sp2 Storage Microsoft Windows Server 2003 Sp2 Enterprise Microsoft Windows Server 2003 Sp2 Datacenter Microsoft Windows Server 2003 SP2 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows Ancillary Function Driver CVE-2012-0149 Local Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with kernel-level privileges. Successful exploits will result in the complete compromise of affected computers.
Microsoft Windows is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with kernel-level privileges. Successful exploits will result in the complete compromise of affected computers.
Exploit / POC
Microsoft Windows Ancillary Function Driver CVE-2012-0149 Local Privilege Escalation Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows Ancillary Function Driver CVE-2012-0149 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more details.
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Microsoft Windows Server 2003 Standard Edition SP2
Solution:
Updates are available. Please see the references for more details.
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB2645640)
http://www.microsoft.com/downloads/details.aspx?familyid=3b18d22d-e192 -498b-a105-b946a5f5bfad
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2645640)
http://www.microsoft.com/downloads/details.aspx?familyid=5ee4bef7-b355 -4aae-8bba-834a16d44744
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB2645640)
http://www.microsoft.com/downloads/details.aspx?familyid=5ee4bef7-b355 -4aae-8bba-834a16d44744
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2645640)
http://www.microsoft.com/downloads/details.aspx?familyid=b53cf810-0ea3 -4cb0-91f9-de1406ccfc96
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2645640)
http://www.microsoft.com/downloads/details.aspx?familyid=b53cf810-0ea3 -4cb0-91f9-de1406ccfc96
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2645640)
http://www.microsoft.com/downloads/details.aspx?familyid=5ee4bef7-b355 -4aae-8bba-834a16d44744
References
Microsoft Windows Ancillary Function Driver CVE-2012-0149 Local Privilege Escalation Vulnerability
References:
References: