Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
BID:56839
Info
Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
| Bugtraq ID: | 56839 |
| Class: | Unknown |
| CVE: |
CVE-2012-1537 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2012 12:00AM |
| Updated: | Dec 11 2012 12:00AM |
| Credit: | Aniway, working with VeriSign iDefense Labs. |
| Vulnerable: |
Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista Ultimate 64-bit edition SP2 Microsoft Windows Vista Service Pack 2 0 Microsoft Windows Vista Home Premium SP2 Microsoft Windows Vista Home Basic SP2 Microsoft Windows Vista Enterprise SP2 Microsoft Windows Server 2008 R2 Itanium SP1 Microsoft Windows Server 2008 R2 Itanium 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 R2 for x64-based Systems 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for 32-bit Systems 0 Microsoft DirectX 9.0 Microsoft DirectX 10.0 |
| Not Vulnerable: | |
Discussion
Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
Microsoft DirectX is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted office documents.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploits will result in denial-of-service conditions.
Microsoft DirectX is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted office documents.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploits will result in denial-of-service conditions.
Exploit / POC
Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows 8 for 32-bit Systems 0
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows Server 2012 0
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows 8 for 64-bit Systems 0
Microsoft Windows Server 2008 for x64-based Systems SP2
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=312975f6-2269 -4c6f-996b-8fb04e8c08d6
Microsoft Windows 8 for 32-bit Systems 0
-
Microsoft Security Update for Windows 8 (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=15f86dbf-d8db -445c-8996-cc789c8a894d
Microsoft Windows 7 for 32-bit Systems SP1
-
Microsoft Security Update for Windows 7 (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=27e57b08-8616 -4eb3-9724-3647e6841296
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Security Update for Windows 7 (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=27e57b08-8616 -4eb3-9724-3647e6841296
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=efe0d293-9cfb -46cb-b52e-0b90bde3f8e9
Microsoft Windows 7 for x64-based Systems SP1
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=5f7c21b9-7dd3 -4b9f-84af-1450af6c7ee3
Microsoft Windows Server 2008 for Itanium-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=0345e31f-6d0d -4d46-8f02-8b2ffbf795f0
Microsoft Windows XP Professional x64 Edition SP2
-
Microsoft Security Update for Windows XP x64 Edition (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=421b0c02-e572 -4362-b690-73ad63b028de
Microsoft Windows Server 2012 0
-
Microsoft Security Update for Windows Server 2012 (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=59be5ec7-df5a -4f01-8e27-ad76f1fe76bb
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=20ffdbfd-c786 -41ca-9367-d7499108d711
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=1b487137-8b5a -4f22-8395-f3fc4f25f00b
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Security Update for Windows 7 for x64-based Systems (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=5f7c21b9-7dd3 -4b9f-84af-1450af6c7ee3
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=39d79b5b-f11c -465a-8ddd-aecb571c711f
Microsoft Windows 8 for 64-bit Systems 0
-
Microsoft Security Update for Windows 8 for x64-based Systems (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=dfdda0c8-a440 -49ab-832b-cdd343c57770
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2770660)
http://www.microsoft.com/downloads/details.aspx?familyid=cfeb7a06-5812 -4a49-b69b-88be06d63d71
References
Microsoft DirectX DirectPlay CVE-2012-1537 Heap Overflow Remote Code Execution Vulnerability
References:
References:
- Microsoft DirectX Homepage (Microsoft)
- Microsoft Security Bulletin MS12-082 (Microsoft)