PT-2011-3019 · Microsoft · Windows Vista+4
J00Ru
+1
·
Published
2011-07-13
·
Updated
2023-12-07
·
CVE-2011-1283
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP versions SP2 through SP3
Microsoft Windows Server 2003 version SP2
Microsoft Windows Vista versions SP1 through SP2
Microsoft Windows Server 2008 versions Gold through SP2
Description
The issue is related to the Client/Server Run-time Subsystem (CSRSS) in the Win32 subsystem, which does not properly validate an array index before performing read and write operations. This allows local users to potentially gain privileges or cause a denial of service due to memory corruption by using a crafted application. The vulnerability is due to the way CSRSS assigns memory for specific user transactions, which could allow an attacker to run arbitrary code in kernel mode.
Recommendations
For Microsoft Windows XP versions SP2 through SP3, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 version SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Vista versions SP1 through SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2008 versions Gold through SP2, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to the CSRSS subsystem to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp