CERT-In Vulnerability Note
CIVN-2010-0263
Microsoft Windows Consent User Interface Privilege Escalation Vulnerability
Original Issue Date:December 15, 2010
Severity Rating: MEDIUM
Systems Affected
- Microsoft Windows Vista Service Pack 1
- Microsoft Windows Vista Service Pack 2
- Microsoft Windows Vista x64 Edition Service Pack 1
- Microsoft Windows Vista x64 Edition Service Pack 2
- Microsoft Windows Server 2008 (32-bit)
- Microsoft Windows Server 2008 (32-bit) Service Pack 2
- Microsoft Windows Server 2008 (x64)
- Microsoft Windows Server 2008 (x64) Service Pack 2
- Microsoft Windows Server 2008 (Itanium)
- Microsoft Windows Server 2008 (Itanium) Service Pack 2
- Microsoft Windows 7 (32-bit)
- Microsoft Windows 7 (x64)
- Microsoft Windows Server 2008 R2 (x64)
- Microsoft Windows Server 2008 R2 (Itanium)
Overview
A privilege escalation vulnerability has been reported in the Consent User Interface (UI) which could be exploited by malicious users to execute arbitrary code with elevated privileges.
Description
This vulnerability exist in the Consent User Interface (UI) when processing a registry key that has been set to a specific value, which could be exploited by malicious users with "SeImpersonatePrivilege" to execute arbitrary code with elevated privileges.
Solution
Apply patches as mentioned in Microsoft Security bulletin
MS10-100
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx
References
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx
VUPEN
http://www.vupen.com/english/advisories/2010/3222
CVE Name
CVE-2010-3961
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|