CERT-In Vulnerability Note
CIVN-2012-0117
Remote Code Execution on Vulnerability in Windows File Handling Component
Original Issue Date:December 12, 2012
Severity Rating: HIGH
Systems Affected
- Microsoft Windows XP Service Pack 3 0
- Microsoft Windows XP Professional x64 Edition SP2
- Microsoft Windows Vista x64 Edition SP2
- Microsoft Windows Vista Service Pack 2 0
- Microsoft Windows Server 2008 R2 Itanium SP1
- Microsoft Windows Server 2008 R2 Itanium 0
- Microsoft Windows Server 2008 R2 for x64-based Systems SP1
- Microsoft Windows Server 2008 R2 for x64-based Systems 0
- Microsoft Windows Server 2008 for x64-based Systems SP2
- Microsoft Windows Server 2008 for Itanium-based SystemsSP2
- Microsoft Windows Server 2008 for 32-bit Systems SP2
- Microsoft Windows Server 2003 x64 SP2
- Microsoft Windows Server 2003 Itanium SP2\
- Microsoft Windows Server 2003 SP2
- Microsoft Windows 7 for x64-based Systems SP1
- Microsoft Windows 7 for x64-based Systems 0
- Microsoft Windows 7 for 32-bit Systems SP1
- Microsoft Windows 7 for 32-bit Systems 0
Overview
A Vulnerability has been reported in Windows File Handling Component which could be exploited by a remote attacker to take complete control of the affected system in the context of logged in user.
Description
The vulnerability occurs when Windows fails to properly handle a specially crafted file or subfolder name which allows data to be copied into memory that has not been properly allocated . A remote attacker could exploit this vulnerability by convincing a user to browse to a file system that contains a file or subfolder with a specially crafted name.
Successful exploitation of this vulnerability could cause a memory error condition that could allow the attacker to execute arbitrary code on the system with the privileges of the user.
Solution
Apply appropriate updates as mentioned in the Microsoft security bulletin
MS12-081
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-081
References
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-081
Security Tracker
http://www.securitytracker.com/id/1027855
Security Focus
http://www.securityfocus.com/bid/56443/info
CVE Name
CVE-2012-4774
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|