Results 1 to 6 of 6
  1. #1
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755

    Vulnerability in Microsoft Malware Protection Engine

    Microsoft Security Advisory (2491888)

    Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege

    Published: February 23, 2011

    Version: 1.0
    General Information
    Executive Summary

    Microsoft is releasing this security advisory to help ensure customers are aware that an update to the Microsoft Malware Protection Engine also addresses a security vulnerability reported to Microsoft. The update addresses a privately reported vulnerability that could allow elevation of privilege if the Microsoft Malware Protection Engine scans a system after an attacker with valid logon credentials has created a specially crafted registry key. An attacker who successfully exploited the vulnerability could gain the same user rights as the LocalSystem account. The vulnerability could not be exploited by anonymous users.

    Since the Microsoft Malware Protection Engine is a part of several Microsoft anti-malware products, the update to the Microsoft Malware Protection Engine is installed along with the updated malware definitions for the affected products. Administrators of enterprise installations should follow their established internal processes to ensure that the definition and engine updates are approved in their update management software, and that clients consume the updates accordingly.

    Typically, no action is required of enterprise administrators or end users to install this update, because the built-in mechanism for the automatic detection and deployment of this update will apply the update within the next 48 hours. The exact time frame depends on the software used, Internet connection, and infrastructure configuration.

    Affected Software

    Vulnerability Severity Rating and Maximum Security Impact by Affected Software
    Anti-malware Software Microsoft Malware Protection Engine Vulnerability - CVE-2011-0037

    Windows Live OneCare


    Important
    Elevation of Privilege

    Microsoft Security Essentials


    Important
    Elevation of Privilege

    Microsoft Windows Defender


    Important
    Elevation of Privilege

    Microsoft Forefront Client Security


    Important
    Elevation of Privilege

    Microsoft Forefront Endpoint Protection 2010


    Important
    Elevation of Privilege

    Microsoft Malicious Software Removal Tool


    Important
    Elevation of Privilege

    Mitigating Factors

    Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of this issue. The following mitigating factors may be helpful in your situation:


    An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.


    An attacker could use the Malicious Software Removal Tool (MSRT) to exploit this vulnerability only if MSRT has not already run on the system. For the majority of end users, the current version of the MSRT will already have downloaded and run automatically through automatic updating.
    Read more:
    http://www.microsoft.com/technet/security/advisory/2491888.mspx

  2. #2
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Thanks for the heads up Leo! As always, it is much appreciated!
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  3. #3
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    the built-in mechanism for the automatic detection and deployment of this update will apply the update within the next 48 hours.
    MSE auto update scheme will do the trick. Thanks
    "Stars and the Sun"


  4. #4
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Thank you for sharing the information Leo, as Ceyfer pointed out auto update will take care of it but it's the mechanics of it that are just as important..
    Stutz Bearcat

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    3,271
    Liked
    155 times
    Points
    6,541
    Thanks leofelix for security advisory info
    Windows 7 SP1 Ultimate x86 + KIS 2011 (11.0.2.556 b.a.c.d) + Sandboxie Paid (3.54) + Deep Freeze Standard (7.20.020.3398)

  6. #6
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Thanks for the heads up captain .
    I don't need to know everything, I just need to know where to find it, when I need it.

 

 

Similar Threads

  1. Microsoft Vulnerability Research/Advisories.
    By Ceyfer √ in forum Security Bulletin
    Replies: 7
    Last Post: 04-21-2011, 02:43 PM
  2. Protection from dll-vulnerability with Winpatrol Plus
    By leofelix in forum Spyware/Viruses
    Replies: 22
    Last Post: 08-31-2010, 07:05 PM
  3. Online Armor ++ (with Anti-Malware realtime protection ?)
    By LAHarry in forum Spyware/Viruses
    Replies: 6
    Last Post: 06-16-2010, 03:08 PM
  4. Replies: 2
    Last Post: 05-08-2010, 05:37 AM
  5. Replies: 6
    Last Post: 11-02-2009, 08:43 AM

Tags for this Thread

All times are GMT +8. The time now is 06:17 AM.