Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: July 6, 2009
Lauren Gerber
7
Vote
0

Warning: New Microsoft Windows Remote Code Execution Vulnerability

 

The world of computer security vulnerabilities has gone completely mad I tell you. More and more vulnerabilities are appearing at an alarming rate. Just when a patch or update is released, a vulnerability comes along and takes its place. The world of vulnerabilities seems to be a vicious never ending cycle at this current point in time. A new vulnerability has unveiled itself, and this time it's a remote code execution vulnerability in none other than Microsoft Windows.

This particular vulnerability was discovered in the wild and affects many versions of Microsoft Windows. It also affects versions of the Windows servers. Some of the files of Windows server 2003 may include but are not by any means limited to the following:a302.sys, b5820w2k.sys, backsnap.dll, CasPol.exe, certobj.dll as well as ctrl_.js.

Some versions of Microsoft Windows which may be vulnerable
Microsoft Windows XP Tablet PC Edition SP3
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows XP Tablet PC Edition SP1
Microsoft Windows XP Tablet PC Edition
Microsoft Windows XP Professional x64 Edition SP3
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Professional SP3
Microsoft Windows XP Professional SP2
Microsoft Windows XP Professional SP1
Microsoft Windows XP Professional
Microsoft Windows XP Media Center Edition SP3
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows XP Media Center Edition SP1
Microsoft Windows XP Media Center Edition

Table 1. Some versions of Microsoft Windows which may be vulnerable

This vulnerability relates to a remote code execution vulnerability that has a direct tendency to affect the TV Tuner library. This vulnerability runs the risk of a malicious attackers being able to exploit it by convincing a specific users to go to websites which have been tampered with. If this vulnerability is exploited with a vast degree of success, then this may allow malicious characters to execute arbitrary code, with regard to the user which is logged in at that specific point in time.6Windows.jpg

There is exploit code available for this vulnerability but users need to be aware that the exploit code is not fully functional, at this point in time. This is due to the factor that the file which is needed to trigger this vulnerability is not supplied. There is no solution to this vulnerability at present, but hopefully there shall be one available in the not too distant future.

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 14, 2010
Hey i just got P2P-Worm.Win32. .. rm.Win32.Palevovirus on my laptop and i dont know how to remove it... more..
March 14, 2010
alot has been plaging me for about three months more..
March 14, 2010
arey you bloody stupid or what? awc.exe belongs to advance system care, idiots! go back to dos and learn... more..
more comments..
rss
Home > Computer Security > Warning: New Microsoft Windows Remote Code Execution Vulnerability