الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

Microsoft Windows Kernel "Win32k.sys" Pool Corruption Vulnerability

بدأه MoHaMMaD Pro في 10 أغسطس 2010 · 1 رد · 670 مشاهدة · في الأخبار والنقاشات التقنية
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم ورحمة الله وبركاته

قام موقع VUPEN Security بالكشف عن ثغرة موجودة في جميع اصدارات نظام التشغيل ويندوز بما فيها Windows 7 و Windows Server 2008 R2

وبحسب الموقع فقد يسبب استغلال هذه الثغرة من قبل المهاجم إلى تحقيق DOS على الجهاز المصاب

تحدث هذه الثغرة بسبب حدوث buffer over flow على الدالة "CreateDIBPalette()"

الموجودة في الملف "Win32k.sys" الذي هو kernel-mode device driver

اعذروني حاولت ترجمة ما يمكن ترجمته ولكن الشرح التقني عن الثغرة لم استطع صياغته بالشكل المناسب

اقتباس

Technical Description

A vulnerability has been identified in Microsoft Windows, which could be exploited by local attackers to cause a denial of service or potentially gain elevated privileges. This issue is caused by a buffer overflow error in the "CreateDIBPalette()" function within the kernel-mode device driver "Win32k.sys" when using the "biClrUsed" member value of a "BITMAPINFOHEADER" structure as a counter while retrieving Bitmap data from the clipboard, which could be exploited by malicious users to crash an affected system or potentially execute arbitrary code with kernel privileges.

VUPEN has confirmed the vulnerability on fully patched Microsoft Windows 7, Windows Server 2008 SP2, Windows Server 2003 SP2, Windows Vista SP2, and Microsoft Windows XP SP3.

Affected Products

Microsoft Windows 7

Microsoft Windows Server 2008 Service Pack 2

Microsoft Windows Server 2008 R2

Microsoft Windows Server 2008

Microsoft Windows Server 2003 Service Pack 2

Microsoft Windows Server 2003 Service Pack 1

Microsoft Windows Vista Service Pack 2

Microsoft Windows Vista Service Pack 1

Microsoft Windows XP Service Pack 3

Microsoft Windows XP Service Pack 2

المصدر

Everything will be fine when we TALK LESS, DO MORE


#2

شكراً على الخبر :)

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

مواضيع مشابهة