Unchecked Buffer in Microsoft Windows Shell

A vulnerability exists in Windows Shell that lets an attacker arbitrarily execute code under the authorized user’s security context.

Ken Pfeil

March 7, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported March 08, 2002, byMicrosoft.

VERSIONS AFFECTED

 

  • Windows 2000, Windows NT 4.0, Windows NT 4.0 Server Terminal Edition, Windows 98 Second Edition (Win98SE), and Windows 98

 

DESCRIPTION
A vulnerability exists in Windows Shell that lets an attacker arbitrarilyexecute code under the authorized user’s security context.An unchecked buffer exists in one of the functions that helps locateincompletely removed applications on the system. As a result, an attacker canmount a buffer-overrun attack and either cause the Windows Shell to crash or canexecute code under the user's security context.

 

VENDOR RESPONSE

Thevendor, Microsoft, has released SecurityBulletin MS02-014to address this vulnerability, and recommends that affected users immediatelyapply the appropriate patch as listed in Security Bulletin MS03-014.

 

CREDIT
Discovered by eEyeDigital Security.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like