SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#259197

Microsoft Client Server Runtime System Vulnerability

Overview

The Microsoft Client Server Runtime System (CSRSS) incorrectly validates certain messages potentially resulting in privilege elevation.

I. Description

CSRSS is the user-mode part of the Win32 subsystem. Win32.sys is the kernel-mode portion of the Win32 subsystem. The Win32 subsystem must be running at all times. CSRSS is responsible for console windows, for creating threads, for deleting threads, and for some parts of the 16-bit virtual MS-DOS environment. The CSRSS only responds to requests made by other processes on the local computer.


A locally authenticated user may be able to exploit a vulnerability in the way CSRSS validates certain messages in order to gain elevated privileges.

II. Impact

Local authenticated users could potentially execute arbitrary code as privileged users, allowing them to gain complete control of the system.

III. Solution

Apply a patch


Microsoft has published Microsoft Security Bulletin MS05-018 in response to this issue. Users are strongly encouraged to review this advisory and apply the patches it refers to.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable13-Apr-2005

References


http://www.microsoft.com/technet/security/bulletin/MS05-018.mspx
http://www.idefense.com/application/poi/display?id=230&type=vulnerabilities&flashstatus=false

Credit

Thanks to Microsoft who in turn thank David Fritz working with iDEFENSE for reporting the CSRSS Vulnerability.

This document was written by Robert Mead based on information provided by Microsoft.

Other Information

Date Public:2005-04-12
Date First Published:2005-04-13
Date Last Updated:2005-05-17
CERT Advisory: 
CVE-ID(s):CAN-2005-0551
NVD-ID(s):CAN-2005-0551
US-CERT Technical Alerts: 
Metric:2.43
Document Revision:14

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader