Microsoft Windows Firewall CVE-2012-0174 Security Bypass Vulnerability
BID:53352
Info
Microsoft Windows Firewall CVE-2012-0174 Security Bypass Vulnerability
| Bugtraq ID: | 53352 |
| Class: | Unknown |
| CVE: |
CVE-2012-0174 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2012 12:00AM |
| Updated: | May 28 2012 07:40PM |
| Credit: | Bojan Zdrnja of INFIGO IS |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista SP2 Microsoft Windows Vista SP1 Microsoft Windows Server 2008 R2 x64 SP1 Microsoft Windows Server 2008 R2 x64 0 Microsoft Windows Server 2008 R2 Itanium SP1 Microsoft Windows Server 2008 R2 Itanium 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for 32-bit Systems 0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows Firewall CVE-2012-0174 Security Bypass Vulnerability
Microsoft Windows is prone to a security-bypass vulnerability that affects the TCP/IP stack ('tcpip.sys') component.
An attacker can exploit this issue to bypass firewall restrictions of the system, that may aid in further attacks.
Microsoft Windows is prone to a security-bypass vulnerability that affects the TCP/IP stack ('tcpip.sys') component.
An attacker can exploit this issue to bypass firewall restrictions of the system, that may aid in further attacks.
Exploit / POC
Microsoft Windows Firewall CVE-2012-0174 Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows Firewall CVE-2012-0174 Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft Windows Vista SP2
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Vista x64 Edition SP2
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Server 2008 for x64-based Systems SP2
Solution:
Vendor updates are available. Please see the references for more information.
Microsoft Windows Vista SP2
-
Microsoft Security Update for Windows Vista (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=b1dc6e10-34eb -45ea-92b3-9983c00f6cb5
Microsoft Windows 7 for 32-bit Systems SP1
-
Microsoft Security Update for Windows 7 (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=46b8749e-3d8f -472f-a1ea-419f44c6bc00
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Security Update for Windows 7 (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=46b8749e-3d8f -472f-a1ea-419f44c6bc00
Microsoft Windows 7 for x64-based Systems SP1
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=e89fb3f1-44cb -4fc0-bbc2-8e94d6933322
Microsoft Windows Server 2008 for Itanium-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=c5f7ee25-2fc1 -44c7-b3e6-e2c969ecf1bc
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=7ef72aab-7fd2 -4330-bb6a-0c77c3943345
Microsoft Windows Vista x64 Edition SP2
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=d65565d4-d865 -438a-bfb7-d71af9dd884e
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=e89fb3f1-44cb -4fc0-bbc2-8e94d6933322
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2688338)
http://www.microsoft.com/downloads/details.aspx?familyid=9569d980-766d -4825-bd1c-f30c93d4b035
References
Microsoft Windows Firewall CVE-2012-0174 Security Bypass Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS12-032 (Microsoft)
- MS12-032 Vulnerability in TCP/IP Could Allow Elevation of Privilege (2688338) (Avaya)