|
|
|
![]() |
Vulnerability Note VU#240796Microsoft Windows Shell vulnerable to privilege escalationOverviewA vulnerability in Microsoft Windows Shell may allow an attacker to gain access with escalated privileges.I. DescriptionThe Microsoft Windows Shell Hardware Detection service provides notification for AutoPlay hardware events. This service fails to properly validate a function parameter in the way that hardware is detected and initialized which may allow access with escalated privileges. An attacker with the ability to run a specially crafted application that forces the system to perform a hardware detection and initialization event, may be able to exploit this vulnerability.II. ImpactA local, authenticated attacker may be able to access the system with escalated privileges. Secondary impacts include: the ability to install programs; view, change or delete data; or create new accounts with full user rights.III. SolutionMicrosoft has released an update to address this issue. Please see Microsoft Security Bulletin MS07-006 for more details.Workaround
2. Double-click Administrative Tools. 3. Double-click Services. 4. Double-click Shell Hardware Detection service. 5. In the Startup type list, click Disabled. 6. Click Stop, and then click OK. Please note that disabling the Shell Hardware Detection service may limit Fast User switching capabilities. Systems Affected
References
This vulnerability was reported in Microsoft Security Bulletin MS07-006. This document was written by Katie Steiner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||