Infesting you with Virus News
 

News

Contributed by: Eglė
Date: June 5, 2009
Eglė
1
Vote
0

The Windows NT Win32k.sys Vulnerability can Trigger an Application Crash

 

180px-Windows_NT_WorkstationOS.PNGAs it is often said, no news is good news, and in many ways this could be true. I say this firstly because I have some news to announce and secondly because the news is indeed bad. Sounds scary, I know. But I'm writing this article not with the intention to frighten you, but to enlighten you on the latest security issues and help you avoid them.

I'm going to introduce you to a ‘hot' vulnerability which recently came up. It punched Microsoft Windows unmercifully. I'm talking about the Microsoft Windows NT 'win32k.sys' Local Denial of Service Vulnerability. Microsoft has confirmed it in Windows NT version 4.0. This security issue was fixed in the latest US Service Pack for Windows NT.

So how does this vulnerability work and spread? Not all Win32K functions, before the release of  SP2, properly validate input parameters. An attacker could write an errant application that sends incorrect parameters to a Win32K function resulting in the access violation of Win32k.sys. This violation would usually lead to Windows NT crashing with a STOP 0x0000001E blue screen error. That is to say that the vulnerability in Win32k.sys in Windows NT 4.0 before SP2, enables malicious users to create a denial of service condition. Affected platforms were confirmed and include the following:

  • Microsoft, Windows NT 3.5.1 SP1;
  • Microsoft, Windows NT 4.0.

Security has been a hot topic with Microsoft for a very long time. Microsoft itself has been the victim of numerous  security holes. Windows NT and its successors are created for security (also on networks) and multi-user PCs. However, at first it was not created with Internet security in mind, as in the early 1990s Internet use was less popular. The design issues associated with flawed code (for example buffer overflows) along with the popularity of Windows means that it's vulnerabilities are a regularly target of cybercriminals. Some of the files of Windows NT 4.0 may include but are not limited to the following:

File names:
rasmon.exe
schdpl32.exe
terminal.exe
calc.exe
rasadmin.exe
CDPLAYER.EXE
NDDEAGNT.EXE
BACKUP.EXE
rcp.exe
EDLIN.EXE
RASMAN.EXE
rasdial.exe
REDIR.EXE
netdde.exe
pbrush.exe
RASPHONE.EXE
LABEL.EXE
CDB.EXE
cdfs.sys
ndis.sys

Table 1.  Files related to Windows NT 4.0

I'm sure you may be asking what can i do?! The answer is, calm down. It is not that bad, and I also have some good news for you. Microsoft has found a solution to this security problem! Users who have encountered this type of vulnerability and want to remedy it are recommended to apply the latest Windows NT 4.0 Service Pack (SP2 or later), available on the Windows NT Service Packs Web page.

 

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Download (Spyware/Trojan Detection), SCAN, BLOCK Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

February 9, 2010
I had the same problem with that Antivirus soft ***. All I did was reboot the computer to safemode... more..
February 8, 2010
Brian xavier- what is the support option you speak of? I just got it yesterday 2/12 since you had it... more..
February 8, 2010
Zlob is one of the most common types of trojan programs used to attack windows these days. In a typical... more..
more comments..
rss
Home > Computer Security > The Windows NT Win32k.sys Vulnerability can Trigger an Application Crash