PT-2014-1736 · Microsoft · Windows Vista+3
Icewall
+1
·
Published
2014-10-14
·
Updated
2019-02-26
·
CVE-2014-4115
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2003 SP2
Microsoft Windows Vista SP2
Microsoft Windows Server 2008 SP2
Description
The issue exists due to the way the Windows FASTFAT system driver interacts with FAT32 disk partitions. This allows an attacker to execute arbitrary code with elevated privileges by connecting a crafted USB device. The vulnerability can be exploited by physically proximate attackers.
Recommendations
For Microsoft Windows Server 2003 SP2, update the FASTFAT driver to a patched version.
For Microsoft Windows Vista SP2, update the FASTFAT driver to a patched version.
For Microsoft Windows Server 2008 SP2, update the FASTFAT driver to a patched version.
As a temporary workaround, consider restricting access to USB devices to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Server 2003
Windows Server 2008
Windows Vista