Vulnerability Note VU#323172
Microsoft Windows browser election message kernel pool overflow
Overview
A vulnerability exists in the way the Microsoft Windows browser service handles Browser Election messages.
Description
From Description of the Microsoft Computer Browser Service: "The browser service maintains a list of the domain name or workgroup name the computer is in, and the protocol being used for each computer on the network segment being served by the computer running the browser service. On each network segment, a master browser is elected from the group of computers located on the segment that are running the browser service." |
Impact
Using a specially crafted Browser Election message, an attacker may be able to cause a Denial of Service (DoS) or execute arbitrary code. |
Solution
Apply an update |
|
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 15 Apr 2011 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/technet/security/bulletin/MS11-019.mspx
- http://blogs.technet.com/b/mmpc/archive/2011/02/16/my-sweet-valentine-the-cifs-browser-protocol-heap-corruption-vulnerability.aspx
- http://blogs.technet.com/b/srd/archive/2011/02/16/notes-on-exploitability-of-the-recent-windows-browser-protocol-issue.aspx
- http://lists.grok.org.uk/pipermail/full-disclosure/2011-February/079189.html
Credit
This document was written by David Warren.
Other Information
- CVE IDs: Unknown
- Date Public: 14 Feb 2011
- Date First Published: 16 Feb 2011
- Date Last Updated: 15 Apr 2011
- Severity Metric: 18.73
- Document Revision: 17
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.