CERT-In Vulnerability Note
CIVN-2014-0227
Multiple Remote Code Execution Vulnerabilities in Kernel-Mode Driver
Original Issue Date:October 15, 2014
Severity Rating: HIGH
Systems Affected
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista SP2
- Windows Vista x64 Edition SP2
- Windows Server 2008 for 32-bit Systems SP2
- Windows Server 2008 for x64-based Systems SP2
- Windows Server 2008 for Itanium-based Systems SP2
- Windows 7 for 32-bit and x64-based Systems SP1
- Windows Server 2008 R2 for x64-based and Itanium-based Systems SP1
- Windows 8 for 32-bit and x64-based Systems
- Windows 8.1 for 32-bit and x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT
- Windows RT 8.1
Overview
Multiple Vulnerabilities have been reported in Windows Kernel Mode Driver which could be exploited by an attacker to execute arbitrary on the affected system.
Description
1. True Type Font Processing Arbitrary code execution Vulnerability
(
CVE-2014-4148
)
The vulnerability exists in the Microsoft Windows kernel mode driver due to improper handling of true type font files. A remote attacker could exploit this vulnerability by sending a crafted TrueType Font file and enticing the user to open the crafted file. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code in context of the logged-in user.
2. Win32k.sys Arbitrary code execution Vulnerability
(
CVE-2014-4113
)
The vulnerability exists in the Microsoft Windows kernel mode driver (Win32k.sys) due to improper handling of objects in the memory. Successful exploitation of this vulnerability could allow a local attacker to execute arbitrary code and take complete control of the affected system.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS14-058
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/ms14-058
References
Security Focus
http://www.securityfocus.com/bid/70364
http://www.securityfocus.com/bid/70429
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=35980
http://tools.cisco.com/security/center/viewAlert.x?alertId=36073
FireEye
http://www.fireeye.com/blog/technical/targeted-attack/2014/10/two-targeted-attacks-two-new-zero-days.html
CVE Name
CVE-2014-4148
CVE-2014-4113
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|