|
|
|
Vulnerability Note VU#411516Microsoft Windows kernel fails to properly manage exception handlingOverviewAn exception handling vulnerability in the Microsoft Windows kernel may allow a remote attacker to execute arbitrary code.I. DescriptionMicrosoft Windows kernel contains an exception handling vulnerability that can allow a remote attacker to execute arbitrary code with privileges of the local user. Exploitation of this vulnerability can occur if an attacker convinces a user to visit a specially crafted web site.Microsoft's bulletin states that the following Windows operating systems are affected by this vulnerability:
II. ImpactA remote attacker who can successfully convince a user visit a specially crafted web site may be able to execute arbitrary code with privileges of the local user.III. SolutionApply an updateMicrosoft has released updates in Microsoft Security Bulletin MS06-051 to address this issue.
Please see the Microsoft Security Bulletin MS06-051 for further details and cautions regarding use of the Registry Editor. Read e-mail messages in plain text format. E-mail messages viewed in plain text will not contain pictures, special fonts, or other rich content. Systems Affected
References
Thanks to Microsoft Security for reporting this vulnerability in Microsoft Security Bulletin MS06-051. Microsoft, in turn, thanks Matt Miller of Leviathan Security Group for reporting the vulnerability to them. This document was written by Katie Washok.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||