Vista Exploit Surfaces on Russian Hacker Site

Reply

Join Date: Jan 2007
Posts: 2
Reputation: c.handy is an unknown quantity at this point 
Solved Threads: 0
c.handy c.handy is offline Offline
Newbie Poster

Vista Exploit Surfaces on Russian Hacker Site

 
0
  #1
Jan 8th, 2007
Proof-of-concept exploit code for a privilege escalation vulnerability affecting all versions of Windows—including Vista—has been posted on a Russian hacker forum, forcing Microsoft to activate its emergency response process.

Mike Reavey, operations manager of the Microsoft Security Response Center, confirmed that the company is “closely monitoring” the public posting, which first appeared on a Russian language forum on Dec. 15. It affects “csrss.exe,” which is the main executable for the Microsoft Client/Server Runtime Server.

According to an alert cross-posted to security mailing lists, the vulnerability is caused by a memory corruption when certain strings are sent through the MessageBox API.

“The PoC reportedly allows for local elevation of privilege on Windows 2000 SP4, Windows Server 2003 SP1, Windows XP SP1, Windows XP SP2 and Windows Vista operating systems,” Reavey said in an entry posted late Dec. 21 on the MSRC blog.
Last edited by happygeek; Jan 11th, 2007 at 12:17 pm. Reason: URL snipped - keep it on-site please
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Windows Vista and Windows 7 Forum
Thread Tools Search this Thread



Tag cloud for Windows Vista and Windows 7
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC