Microsoft Windows NT Win32k.sys Denial of Service Vulnerability
BID:6742
Info
Microsoft Windows NT Win32k.sys Denial of Service Vulnerability
| Bugtraq ID: | 6742 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2000 12:00AM |
| Updated: | Feb 24 2000 12:00AM |
| Credit: | This vulnerability appears to have been announced by Microsoft. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 |
| Not Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 |
Discussion
Microsoft Windows NT Win32k.sys Denial of Service Vulnerability
Some Win32K functions incorrectly validate input parameters prior to NT Service Pack 2.
This problem could allow an attacker to write an application that passes malformed parameters to a Win32K function which may result in a critical system failure.
Exploitation would require that the attacker can cause the application to be executed on a vulnerable system. Reportedly, this could also be exploited through an ActiveX control residing on a maliciously constructed website.
Some Win32K functions incorrectly validate input parameters prior to NT Service Pack 2.
This problem could allow an attacker to write an application that passes malformed parameters to a Win32K function which may result in a critical system failure.
Exploitation would require that the attacker can cause the application to be executed on a vulnerable system. Reportedly, this could also be exploited through an ActiveX control residing on a maliciously constructed website.