Infesting you with Virus News
 

Vulnerabilities

win32k.sys in Microsoft Windows Server 2003 and Vista DDOS vulnerability (PC1-2009-1471)

Overview

Vulnerability chart

Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
73 vulnerabilities(-y) found between 10 July, 2003 and 14 July, 2009.
Windows Server 2003 (known as Win2K3) points to a server operating system... more
See also: Windows Server 2003 SP1, Windows Server 2003 SP2, Windows Server 2003 x64, Windows Server 2003 x64 SP2, Windows 2003
518 files found: owsadm.exe, w3wp.exe, httpcfg.exe, wmseditor.exe, dsrm.exe, IEExec.exe, dcgpofix.exe, portqry.exe, msppcnfg.exe, cmdkey.exe, addusr.exe, tapicfg.exe, dsget.exe, dsadd.exe, pop3svc.exe... more
Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
44 vulnerabilities(-y) found between 4 April, 2007 and 12 January, 2010.
Windows Vista relates to a line of operating systems. It is created by... more
See also: Windows Vista SP1, Windows Vista x64, Vista
5202 files found: mrt.exe, memtest.exe, setuposk.exe, rollback.exe, msmig.exe, bootsect.exe, migautoplay.exe, netfxupdate.exe, sperr32.exe, mighost.exe, installmw.exe, migsetup.exe, pkgmgr.exe, cableinst.exe, imtcmig.dll... more
Vulnerability was discovered in win32k.sys in Microsoft Windows Server 2003 and Vista.
DDOS
Unknown patch
availability
Patch implementation
unknown

References to Advisories, Solutions, and Tools

Description:

By using this particular vulnerability, local users are enabled to cause a denial of service that is system crash. This may be done through vectors pertaining to CreateWindow, TranslateMessage, and DispatchMessage, in some way a race condition between threads, a different vulnerability than CVE-2008-1084. It should be mentioned that some of these details are gained from third party information.

Impact:

With the help of this type of vulnerability, local users are enabled to break up a service.

References:http://www.securityfocus.com/data/vulnerabilities/exploits/35121.c
http://www.securityfocus.com/bid/35121
http://bugtraq.ru/cgi-bin/forum.mcgi?type=sb&b=2&m=152274

Impact

CVSS Severity

CVSS Version 2 Metrics:

CVSS v2 Base Score:4.7 (MEDIUM)Access Vector:N/A
Impact Subscore: 6.9Access Complexity: Medium
Exploitability Subscore: 3.4Authentication: Not required to exploit
Impact Type:Allows disruption of serviceUnknown

Say something interesting!

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Latest Comments

March 17, 2010
March 17, 2010
Found this list of godaddy domain name coupons, I got a domain for my dog - ha $6.91 Domain... more..
March 17, 2010
Three guys were having a beer in a bar in London. They were all relative newly-weds and they were talking... more..
more comments..
rss
Home > Vulnerabilities > pc1-2009-1471