Content

(MS09-065) Win32k EOT Parsing Vulnerability (969947)

Type
Logic error
Impact of exploitation
Remote Code Execution
User Interaction
no user interaction is needed
Attack Vector
Website with malicious content
Rating
Medium
CVE reference
CVE-2009-2514,
Vendor Status
Responded and patched
Vulnerable systems
Windows  2000 SP4,
Windows  XP SP3,
Windows  XP X64 Professional,
Windows Server 2003  2003 SP2,
Windows Server 2003  Itanium SP2,
Summary
A critical remote code execution vulnerability exists in Windows kernel-mode drivers.

Tab Navigation

Description

The vulnerability exists because of the improper parsing of font code when building a table of directory entries. Successful exploitation of the vulnerability could allow an attacker to run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

McAfee Product Mitigation & Recommendations

Recommendations

The Vendor has released patches to address this issue http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS09-065) Win32k EOT Parsing Vulnerability (969947)
Signature identifier:
7318
Release date:
11/10/2009

Additional Resources

(MS09-065) Win32k EOT Parsing Vulnerability (969947)

http://www.microsoft.com/technet/security/bulletin/ms09-0xx.mspx

All Information

Timeline -

11/10/2009

Vendor has provided a patch.

Description -

The vulnerability exists because of the improper parsing of font code when building a table of directory entries. Successful exploitation of the vulnerability could allow an attacker to run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

McAfee Product Mitigation & Recommendations

Recommendations -

The Vendor has released patches to address this issue http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS09-065) Win32k EOT Parsing Vulnerability (969947)
Signature identifier:
7318
Release date:
11/10/2009

Additional Resources

Additional Resources -

(MS09-065) Win32k EOT Parsing Vulnerability (969947)

http://www.microsoft.com/technet/security/bulletin/ms09-0xx.mspx