Vulnerabilities > CVE-2010-1889 - Resource Management Errors vulnerability in Microsoft Windows Server 2008 and Windows Vista
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 11 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Microsoft Windows KTM Invalid Free with Reused Transaction GUID (MS10-047). CVE-2010-1889. Dos exploit for windows platform |
id | EDB-ID:14667 |
last seen | 2016-02-01 |
modified | 2010-08-17 |
published | 2010-08-17 |
reporter | Tavis Ormandy |
source | https://www.exploit-db.com/download/14667/ |
title | Microsoft Windows KTM Invalid Free with Reused Transaction GUID MS10-047 |
Msbulletin
bulletin_id | MS10-047 |
bulletin_url | |
date | 2010-08-10T00:00:00 |
impact | Elevation of Privilege |
knowledgebase_id | 981852 |
knowledgebase_url | |
severity | Important |
title | Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS10-047.NASL |
description | The remote Windows host is running a version of the Windows kernel that is affected by one or more of the following vulnerabilities : - A race condition when creating certain types of kernel threads may allow a local attacker to execute arbitrary code in kernel mode and take complete control of the affected system. (CVE-2010-1888) - A double free vulnerability when the kernel initializes objects while handling certain errors may allow a local attacker to execute arbitrary code in kernel mode and take complete control of the affected system. (CVE-2010-1889) - A failure to properly validate access control lists on kernel objects may allow a local attacker to cause the system to become unresponsive and automatically restart. (CVE-2010-1890) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 48284 |
published | 2010-08-11 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/48284 |
title | MS10-047: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852) |
code |
|
Oval
accepted | 2010-09-27T04:00:03.846-04:00 | ||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||
description | Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability." | ||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:11044 | ||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||
submitted | 2010-08-10T13:00:00 | ||||||||||||||||||||||||||||||||||||||||
title | Windows Kernel Double Free Vulnerability | ||||||||||||||||||||||||||||||||||||||||
version | 72 |
Packetstorm
data source | https://packetstormsecurity.com/files/download/92845/mswinktm-invalidfree.txt |
id | PACKETSTORM:92845 |
last seen | 2016-12-05 |
published | 2010-08-17 |
reporter | Tavis Ormandy |
source | https://packetstormsecurity.com/files/92845/Microsoft-Windows-KTM-Invalid-Free-With-Reused-Transaction-GUID.html |
title | Microsoft Windows KTM Invalid Free With Reused Transaction GUID |
Seebug
bulletinFamily exploit description No description provided by source. id SSV:69612 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-69612 title Microsoft Windows KTM Invalid Free with Reused Transaction GUID (MS10-047) bulletinFamily exploit description BUGTRAQ ID: 42213 CVE ID: CVE-2010-1889 Microsoft Windows是微软发布的非常流行的操作系统。 Windows内核在处理某些出错情况时没有正确地初始化对象,可能导致双重释放。本地用户可以通过运行恶意应用程序获得内核级权限提升。成功利用这个漏洞的攻击者可以执行任意内核态代码。攻击者可随后安装程序;查看、更改或删除数据;或者创建拥有完全用户权限的新帐户。 Microsoft Windows Vista SP2 Microsoft Windows Vista SP1 Microsoft Windows Server 2008 SP2 Microsoft Windows Server 2008 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS10-047)以及相应补丁: MS10-047:Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852) 链接:http://www.microsoft.com/technet/security/bulletin/MS10-047.mspx?pf=true id SSV:20038 last seen 2017-11-19 modified 2010-08-12 published 2010-08-12 reporter Root title Windows内核双重释放本地权限提升漏洞(MS10-047)
References
- http://www.us-cert.gov/cas/techalerts/TA10-222A.html
- http://www.us-cert.gov/cas/techalerts/TA10-222A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-047
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-047
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11044
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11044