Vulnerabilities > CVE-2010-3940 - Resource Management Errors vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 18 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS10-098 |
bulletin_url | |
date | 2010-12-14T00:00:00 |
impact | Elevation of Privilege |
knowledgebase_id | 2436673 |
knowledgebase_url | |
severity | Important |
title | Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS10-098.NASL |
description | The remote host is running a version of Windows that contains a flaw in the kernel that may lead to a privilege escalation by running a specially crafted application. To exploit this vulnerability an attacker must have valid logon credentials and be able to log on locally. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 51170 |
published | 2010-12-15 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/51170 |
title | MS10-098: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) |
code |
|
Oval
accepted | 2014-03-03T04:00:18.386-05:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
description | Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability." | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:12194 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2010-08-10T13:00:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
title | Win32k PFE Pointer Double Free Vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
version | 80 |
Seebug
bulletinFamily | exploit |
description | CVE ID: CVE-2010-3943,CVE-2010-3944,CVE-2010-3939,CVE-2010-3940,CVE-2010-3941,CVE-2010-3942 Microsoft Windows是微软发布的非常流行的操作系统。 Microsoft Windows在实现上存在多个漏洞,本地攻击者可利用这些漏洞导致拒绝服务或提升自己的权限。 此漏洞源于: 1)"win32k.sys"驱动程序在从用户模式复制数据时存在内存分配错误,导致在内核中执行任意代码; 2)"win32k.sys"驱动程序在处理PFE对象时存在双重释放错误,导致在内核中执行任意代码; 3)"win32k.sys"驱动程序在运行16位程序时存在双重释放错误,导致在内核中执行任意代码; 4)"win32k.sys"驱动程序在从用户模式复制数据时存在内存分配错误,导致在内核中执行任意代码; 5)"win32k.sys"驱动程序在链接驱动程序对象时存在逻辑错误,导致破坏链接的列表; 6)"win32k.sys"驱动程序在处理用户模式数据时存在输入验证错误,导致内存破坏。 Microsoft Windows XP Microsoft Vista Microsoft Server 2008 Microsoft Windows 7 AVAYA Meeting Exchange 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS10-098)以及相应补丁: MS10-098:Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) http://www.microsoft.com/technet/security/bulletin/MS10-098.asp |
id | SSV:20300 |
last seen | 2017-11-19 |
modified | 2010-12-19 |
published | 2010-12-19 |
reporter | Root |
title | Microsoft Windows "Win32k.sys" 驱动程序多个安全漏洞(MS10-098) |
References
- http://www.securitytracker.com/id?1024880
- http://www.securitytracker.com/id?1024880
- http://www.us-cert.gov/cas/techalerts/TA10-348A.html
- http://www.us-cert.gov/cas/techalerts/TA10-348A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-098
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-098
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12194
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12194