Unchecked Buffer in Microsoft Windows Shell
A vulnerability exists in Windows Shell that lets an attacker arbitrarily execute code under the authorized user’s security context.
March 7, 2002
Reported March 08, 2002, byMicrosoft.
VERSIONS AFFECTED
Windows 2000, Windows NT 4.0, Windows NT 4.0 Server Terminal Edition, Windows 98 Second Edition (Win98SE), and Windows 98
DESCRIPTION
A vulnerability exists in Windows Shell that lets an attacker arbitrarilyexecute code under the authorized user’s security context.An unchecked buffer exists in one of the functions that helps locateincompletely removed applications on the system. As a result, an attacker canmount a buffer-overrun attack and either cause the Windows Shell to crash or canexecute code under the user's security context.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-014to address this vulnerability, and recommends that affected users immediatelyapply the appropriate patch as listed in Security Bulletin MS03-014.
CREDIT
Discovered by eEyeDigital Security.
Read more about:
MicrosoftAbout the Author
You May Also Like