Secunia Logo  


Secunia PSI WorldMap
 
Microsoft Windows Privilege Escalation Vulnerabilities
Secunia Advisory: SA29867
Release Date: 2008-04-18
Last Update: 2009-04-30
Popularity: 14,577 views

Critical:
Less critical
Impact: Privilege escalation
System access
Where: From remote
Solution Status: Vendor Patch

OS:Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Server 2008
Microsoft Windows Storage Server 2003
Microsoft Windows Vista
Microsoft Windows XP Professional

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply patches.

Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/de...=52B756E7-636F-4D9E-8A17-DBF467BFBE4D

NOTE: On 2009-04-29 Microsoft has re-released the Norwegian-language update for Microsoft Windows 2000 Service Pack 4 to fix an error that could cause the installation to fail. No other updates or locales are affected.

Windows XP SP2/SP3:
http://www.microsoft.com/downloads/de...=90FE715E-8190-43E9-9C43-DF5BE564D923
http://www.microsoft.com/downloads/de...=73d2324f-be59-4b0c-b1ac-9876a13c2c03

Windows XP Professional x64 Edition (optionally with SP2):
http://www.microsoft.com/downloads/de...=A794C32A-9A0C-47D9-9C57-FF5D4A8E4944
http://www.microsoft.com/downloads/de...=b2f12ae5-0e46-47e1-ac5b-93550d030189

Windows Server 2003 SP1/SP2:
http://www.microsoft.com/downloads/de...=25ADEC10-DB8C-4CAC-BF74-2C784678150A
http://www.microsoft.com/downloads/de...=42aba890-8b76-4c5a-8fb6-609797d19831

Windows Server 2003 x64 Edition (optionally with SP2):
http://www.microsoft.com/downloads/de...=B014C399-F404-4CB2-8F9D-864DF382EFEB
http://www.microsoft.com/downloads/de...=a0609f65-82d9-4d82-9f48-f3266e8de123

Windows Server 2003 with SP1/SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/de...=6ADA372B-BA17-433E-B022-D2C57B35AF8A
http://www.microsoft.com/downloads/de...=fda8837c-e5d2-4489-9b44-4c24a1102e77

Windows Vista (optionally with SP1):
http://www.microsoft.com/downloads/de...=F111B99A-E555-4F29-8D1F-E9EC03D5CF1F
http://www.microsoft.com/downloads/de...=d0ea1598-45cb-4c79-8945-caae98969675

Windows Vista x64 Edition (optionally with SP1):
http://www.microsoft.com/downloads/de...=FA153BDC-6B48-4DF2-9E5E-ABACD6DA782C
http://www.microsoft.com/downloads/de...=6dd82f4b-bb33-41ec-90a7-9ef91329b240

Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/de...=9E3C7B52-65A7-42FB-BEB5-1B374934737F
http://www.microsoft.com/downloads/de...=d58702af-bbf8-4f1b-ae72-ced9ef23d581

Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/de...=EEBB4D4D-29D2-4247-8CBB-63A3B17585EC
http://www.microsoft.com/downloads/de...=20bf4e9b-909b-4bc3-ae43-322d74a4f1c3

Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/de...=CC383C24-B0F6-47C1-9E89-6A378B09E82F
http://www.microsoft.com/downloads/de...=bcc2b18f-67db-4109-a9f4-764f985423ee

Provided and/or discovered by:
Cesar Cerrudo, Argeniss

Changelog:
2008-10-09: Updated credits and the "Original Advisory" section.
2009-04-14: Updated "Solution" section and "Original Advisory" sections. Added additional vulnerability information to the advisory. Added "Microsoft Windows 2000" to the list of affected products.
2009-04-30: Added note to the "Solution" section regarding an error with the Norwegian-language update for Microsoft Windows 2000 Service Pack 4.

Original Advisory:
Microsoft (KB951306):
http://www.microsoft.com/technet/security/advisory/951306.mspx

Microsoft (KB959454, KB952004, KB956572):
http://www.microsoft.com/technet/security/bulletin/ms09-012.mspx

Argeniss:
http://www.argeniss.com/research/TokenKidnapping.pdf

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

24th Nov, 2009
New advisories: 8
New vulnerabilities: 19
Updated advisories: 13

Highly // 198 views
SUSE Update for Multiple Packages
Less // 189 views
Debian update for php-mail
Less // 230 views
Fedora update for snort
Not // 209 views
Fedora update for asterisk

23rd Nov, 2009
New advisories: 16
New vulnerabilities: 116
Updated advisories: 33


Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. WordPress WP-Cumulus Plugin "tagcloud" Cross-Site Scripting Vulnerability // 54 views
2. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 48 views
3. Internet Explorer Layout Handling Memory Corruption Vulnerability // 39 views
4. Firefox Sage Extension Cross-Context Scripting Vulnerability // 37 views
5. Sun Java JDK / JRE Multiple Vulnerabilities // 35 views
6. Adobe Flash Player Multiple Vulnerabilities // 34 views
7. PEAR Net_Ping Command Injection Vulnerability // 31 views
8. Adobe Reader/Acrobat Multiple Vulnerabilities // 30 views
9. Opera Multiple Vulnerabilities // 29 views
10. Firefox infoRSS Extension Cross-Context Scripting Vulnerability // 28 views