SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#240796

Microsoft Windows Shell vulnerable to privilege escalation

Overview

A vulnerability in Microsoft Windows Shell may allow an attacker to gain access with escalated privileges.

I. Description

The Microsoft Windows Shell Hardware Detection service provides notification for AutoPlay hardware events. This service fails to properly validate a function parameter in the way that hardware is detected and initialized which may allow access with escalated privileges. An attacker with the ability to run a specially crafted application that forces the system to perform a hardware detection and initialization event, may be able to exploit this vulnerability.

II. Impact

A local, authenticated attacker may be able to access the system with escalated privileges. Secondary impacts include: the ability to install programs; view, change or delete data; or create new accounts with full user rights.

III. Solution

Microsoft has released an update to address this issue. Please see Microsoft Security Bulletin MS07-006 for more details.

Workaround

Disable the Shell Hardware Detection service

Disabling the Shell Hardware Detection service will help protect the affected system from attempts to exploit this vulnerability. To disable the Shell Hardware Detection service, follow these steps:

    1. Click Start, and then click Control Panel. Alternatively, point to Settings, and then click Control Panel.
    2. Double-click Administrative Tools.
    3. Double-click Services.
    4. Double-click Shell Hardware Detection service.
    5. In the Startup type list, click Disabled.
    6. Click Stop, and then click OK.

Please note that disabling the Shell Hardware Detection service may limit Fast User switching capabilities.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable15-Feb-2007

References


http://www.microsoft.com/technet/security/bulletin/ms07-006.mspx
http://secunia.com/advisories/24126/
http://securitytracker.com/alerts/2007/Feb/1017633.html

Credit

This vulnerability was reported in Microsoft Security Bulletin MS07-006.

This document was written by Katie Steiner.

Other Information

Date Public:2007-02-13
Date First Published:2007-02-15
Date Last Updated:2007-02-22
CERT Advisory: 
CVE-ID(s):CVE-2007-0211
NVD-ID(s):CVE-2007-0211
US-CERT Technical Alerts: 
Metric:9.14
Document Revision:12

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader