-
Moderator
Vulnerability in Microsoft Malware Protection Engine
Microsoft Security Advisory (2491888)
Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege
Published: February 23, 2011
Version: 1.0
General Information
Executive Summary
Microsoft is releasing this security advisory to help ensure customers are aware that an update to the Microsoft Malware Protection Engine also addresses a security vulnerability reported to Microsoft. The update addresses a privately reported vulnerability that could allow elevation of privilege if the Microsoft Malware Protection Engine scans a system after an attacker with valid logon credentials has created a specially crafted registry key. An attacker who successfully exploited the vulnerability could gain the same user rights as the LocalSystem account. The vulnerability could not be exploited by anonymous users.
Since the Microsoft Malware Protection Engine is a part of several Microsoft anti-malware products, the update to the Microsoft Malware Protection Engine is installed along with the updated malware definitions for the affected products. Administrators of enterprise installations should follow their established internal processes to ensure that the definition and engine updates are approved in their update management software, and that clients consume the updates accordingly.
Typically, no action is required of enterprise administrators or end users to install this update, because the built-in mechanism for the automatic detection and deployment of this update will apply the update within the next 48 hours. The exact time frame depends on the software used, Internet connection, and infrastructure configuration.
Affected Software
Vulnerability Severity Rating and Maximum Security Impact by Affected Software
Anti-malware Software Microsoft Malware Protection Engine Vulnerability - CVE-2011-0037
Windows Live OneCare
Important
Elevation of Privilege
Microsoft Security Essentials
Important
Elevation of Privilege
Microsoft Windows Defender
Important
Elevation of Privilege
Microsoft Forefront Client Security
Important
Elevation of Privilege
Microsoft Forefront Endpoint Protection 2010
Important
Elevation of Privilege
Microsoft Malicious Software Removal Tool
Important
Elevation of Privilege
Mitigating Factors
Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of this issue. The following mitigating factors may be helpful in your situation:
•
An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.
•
An attacker could use the Malicious Software Removal Tool (MSRT) to exploit this vulnerability only if MSRT has not already run on the system. For the majority of end users, the current version of the MSRT will already have downloaded and run automatically through automatic updating.
Read more:
http://www.microsoft.com/technet/security/advisory/2491888.mspx
-
I'd rather be fishing!
Thanks for the heads up Leo! As always, it is much appreciated!
Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!
-
Guest
the built-in mechanism for the automatic detection and deployment of this update will apply the update within the next 48 hours.
MSE auto update scheme will do the trick. Thanks
"Stars and the Sun"
-
Moderator
Thank you for sharing the information Leo, as Ceyfer pointed out auto update will take care of it but it's the mechanics of it that are just as important..
-
Experienced User
Thanks leofelix for security advisory info
Windows 7 SP1 Ultimate x86 + KIS 2011 (11.0.2.556 b.a.c.d) + Sandboxie Paid (3.54) + Deep Freeze Standard (7.20.020.3398)
-
The Specialist *
Thanks for the heads up captain
.
I don't need to know everything, I just need to know where to find it, when I need it. 
Similar Threads
-
By Ceyfer √ in forum Security Bulletin
Replies: 7
Last Post: 04-21-2011, 02:43 PM
-
By leofelix in forum Spyware/Viruses
Replies: 22
Last Post: 08-31-2010, 07:05 PM
-
By LAHarry in forum Spyware/Viruses
Replies: 6
Last Post: 06-16-2010, 03:08 PM
-
By leofelix in forum Security Bulletin
Replies: 2
Last Post: 05-08-2010, 05:37 AM
-
By polinom in forum Freebies!
Replies: 6
Last Post: 11-02-2009, 08:43 AM
Tags for this Thread
All times are GMT +8. The time now is 06:17 AM.