Информационная безопасность
[RU] switch to
English Version



CVECVE-2006-6696
СтатусCandidate
ОписаниеDouble-free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
ВажностьHigh
CVSS score7
CVSS vector(AV:L/AC:L/Au:NR/C:C/I:C/A:C/B:N)
PhaseAssigned (21.12.2006)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6696
ReferencesBID : 21688
 BUGTRAQ : 20061221 Microsoft Windows XP/2003/Vista memory corruption 0day
 BUGTRAQ : 20061221 Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day
 BUGTRAQ : 20061221 Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memorycorruption 0day
 BUGTRAQ : 20061222 Re: Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day
 BUGTRAQ : 20061230 csrss.exe double-free vulnerability - arbitrary DWORD overwrite exploit
 CONFIRM : http://blogs.technet.com/msrc/archive/2006/12/22/n...
 FRSIRT : ADV-2006-5120
 FRSIRT : ADV-2007-1325
 FULLDISC : 20061221 Microsoft Windows XP/2003/Vista memory corruption 0day
 HP : HPSBST02208
 HP : SSRT071365
 MILW0RM : 2967
 MISC : http://groups.google.ca/group/microsoft.public.win...
 MISC : http://isc.sans.org/diary.php?n&storyid=1965
 MISC : http://research.eeye.com/html/alerts/zeroday/20061...
 MISC : http://www.determina.com/security.research/vulnera...
 MISC : http://www.kuban.ru/forum_new/forum2/files/19124.html
 MISC : http://www.security.nnov.ru/files/messagebox.c
 MISC : http://www.security.nnov.ru/Gnews944.html
 MS : MS07-021
 SECTRACK : 1017433
 SECUNIA : 23448
SecurityVulns:Повреждение памяти в Microsoft Windows (memory corruption)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server