Microsoft Windows Briefcase CVE-2012-1527 Integer Underflow Remote Code Execution Vulnerability
BID:56424
Info
Microsoft Windows Briefcase CVE-2012-1527 Integer Underflow Remote Code Execution Vulnerability
| Bugtraq ID: | 56424 |
| Class: | Unknown |
| CVE: |
CVE-2012-1527 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2012 12:00AM |
| Updated: | Mar 19 2015 09:30AM |
| Credit: | Tal Zeltzer, working with VeriSign iDefense Labs |
| Vulnerable: |
Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista Service Pack 2 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 R2 for x64-based Systems 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for 32-bit Systems 0 Avaya Messaging Application Server 5.2 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Briefcase CVE-2012-1527 Integer Underflow Remote Code Execution Vulnerability
Microsoft Windows Briefcase is prone to a a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed attempts may trigger a denial-of-service condition.
Microsoft Windows Briefcase is prone to a a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed attempts may trigger a denial-of-service condition.
Exploit / POC
Microsoft Windows Briefcase CVE-2012-1527 Integer Underflow Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows Briefcase CVE-2012-1527 Integer Underflow Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Microsoft Windows 8 for 32-bit Systems 0
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows Server 2012 0
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows Vista x64 Edition SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows 8 for 64-bit Systems 0
Solution:
Updates are available. Please see the references for more information.
Microsoft Windows 8 for 32-bit Systems 0
-
Microsoft Security Update for Windows 8 (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=d7c93ade-f7e3 -4b6f-b93d-894ca313282f
Microsoft Windows 7 for 32-bit Systems SP1
-
Microsoft Security Update for Windows 7 (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=22ab8987-2506 -433f-9f12-0ab60d569949
Microsoft Windows 7 for x64-based Systems SP1
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=fc70708e-9de9 -4618-b0ab-d9aa3e2baea0
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=258048b5-d992 -4821-8836-72262a7b5bb7
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=0383bdea-53d1 -4799-b380-14da1595882a
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=fc70708e-9de9 -4618-b0ab-d9aa3e2baea0
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=1c067cb2-71a5 -4f8d-9b11-243c9e5318ce
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=36962e96-0eaa -45a9-b2d6-6bec3242c73e
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=800cd622-d271 -41a4-bd21-a76177d2b272
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Security Update for Windows 7 (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=22ab8987-2506 -433f-9f12-0ab60d569949
Microsoft Windows Server 2012 0
-
Microsoft Security Update for Windows Server 2012 (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=ad6189ae-9341 -409b-a53e-486fef094fd0
Microsoft Windows XP Professional x64 Edition SP2
-
Microsoft Security Update for Windows XP x64 Edition (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=a736c3f0-0326 -4a0a-9c12-f61bafa537bb
Microsoft Windows Vista x64 Edition SP2
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=31f5ad28-ffe9 -4370-b3fc-62eb9fc0c4dd
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=615a96fe-88a5 -498b-ae20-bbfc43e3b652
Microsoft Windows 8 for 64-bit Systems 0
-
Microsoft Security Update for Windows 8 for x64-based Systems (KB2727528)
http://www.microsoft.com/downloads/details.aspx?familyid=7c4a17b7-bb7f -456c-9cb3-3a355e192734
References
Microsoft Windows Briefcase CVE-2012-1527 Integer Underflow Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- ASA-2012-475: (MS12-072) Vulnerabilities in Windows Shell (Avaya)
- Microsoft Security Bulletin MS12-072 (Microsoft)