| To: | full-disclosure@lists.grok.org.uk |
|---|---|
| Subject: | Microsoft Windows XP/2003/Vista memory corruption 0day |
| From: | 3APA3A <3APA3A@SECURITY.NNOV.RU> |
| Date: | Thu, 21 Dec 2006 14:58:17 +0300 |
| Cc: | bugtraq@securityfocus.com |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
| Organization: | http://www.security.nnov.ru |
| Reply-to: | 3APA3A <3APA3A@SECURITY.NNOV.RU> |
Dear full-disclosure@lists.grok.org.uk, Since it's already wide spread on the public forums and exploit is published on multiple sites and there is no way to stop it, I think it's time to alert lists about this. On the one of Russian forums: http://www.kuban.ru/forum_new/forum2/files/19124.html message was published by NULL about vulnerability in Windows on processing MessageBox() with MB_SERVICE_NOTIFICATION flag and message/caption beggining with \??\. Vulnerability seems to be memory corruption in kernel and causes system crash or hang after few attempts. It seems to happen because message is logged to event log and may point to some problem with event logs processing. Vulnerability details and code may be found here: http://www.security.nnov.ru/Gnews944.html There is potential remote exploitation vector if some service uses user-supplied input for MessageBox() function. Messenger service is not vulnerable in this way, because it prepends user-supplied input with additional string. I contacted Microsoft on this issue on December, 16. -- http://www.security.nnov.ru /\_/\ { , . } |\ +--oQQo->{ ^ }<-----+ \ | ZARAZA U 3APA3A } You know my name - look up my number (The Beatles) +-------------o66o--+ / |/ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Oracle <= 9i / 10g File System Access via utl_file Exploit, Marco Ivaldi |
|---|---|
| Next by Date: | Re[2]: [Full-disclosure] Fun with event logs (semi-offtopic), 3APA3A |
| Previous by Thread: | Fun with event logs (semi-offtopic), 3APA3A |
| Next by Thread: | Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day, 3APA3A |
| Indexes: | [Date] [Thread] [Top] [All Lists] |