Results 1 to 3 of 3
  1. #1
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755

    Vulnerability in Canonical Display Driver Could Allow Remote Code Execution (2028859)

    CDD.dll vulnerability: Difficult to exploit (Microsoft Security & Rsearch)

    Today we released security advisory 2028859 notifying customers of a vulnerability in cdd.dll. We wanted to share more information about the public disclosure, exploitability, attack vectors, and workarounds here to help you understand the risk posed by this publicly-disclosed vulnerability.

    Exploitability

    In fact, exploiting this issue for code execution would be tricky. The attacker controls the content, size, and part of the destination of a memory overwrite. However, the attacker does not control the source pointer, so it is very difficult to exploit. With Address Space Layout Randomization (ASLR), it becomes even more difficult. So this one is likely to remain a potential denial-of-service vulnerability and less likely to result in code execution.

    Attack Vectors


    Since becoming aware of the forum discussions, we have been looking for ways to hit this vulnerability with Microsoft software. So far, we haven’t found a remote vector. We’re still looking and meanwhile managed to hit the vulnerable code by executing a specially-crafted program on a machine in the following configuration:

    * Windows 7 X64 machine
    * WDDM 1.1 capable video card (DirectX 10, DirectX 10.1, DirectX 11)
    * Aero glass theme enabled

    Therefore, a malicious attacker able to logon locally to a vulnerable machine matching the above criteria could run a malicious executable to trigger this issue. Users of third-party image viewers may be vulnerable to this issue when viewing an untrusted image with a third-party image viewer locally on the machine.

    Workaround

    If you are concerned about this vulnerability, please temporarily disable the Aero glass theme on vulnerable Windows 7 X64 machines (Aero is not enabled in Windows Server 2008 R2). The advisory lists the steps to help you do so. You can safely re-enable the Aero desktop theme when the security update becomes available.
    Source


    Microsoft Security Advisory (2028859)
    Last edited by leofelix; 05-20-2010 at 01:00 AM. Reason: added source
    Roger and out

  2. #2
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    I thought by Canonical, you meant Ubuntu... That was a rather interesting look on my face of "Linux is now a virus?"
    pacman -Syyu life not found in sync db

  3. #3
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    LOL, I was waiting for your reply indeed:-)

    [edit to add] there is no exploit, even if an Heap Spraying attack could seriosly damage a x64 Windows 7
    Last edited by leofelix; 05-20-2010 at 05:04 AM. Reason: adeed kind of attack

 

 

Similar Threads

  1. Having problems with my Nvidia Display driver
    By BigGuy in forum Hardware
    Replies: 18
    Last Post: 01-01-2012, 10:49 PM
  2. Replies: 0
    Last Post: 06-23-2011, 12:46 AM
  3. Replies: 2
    Last Post: 09-11-2010, 04:09 AM
  4. Replies: 10
    Last Post: 07-22-2010, 01:57 AM
  5. Opera Zero Day Remote Code Execution Vulnerability
    By shan in forum Spyware/Viruses
    Replies: 8
    Last Post: 10-30-2008, 08:55 PM

Tags for this Thread

All times are GMT +8. The time now is 07:46 AM.