Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
Microsoft Windows XP SP2 및 SP3, Windows Server 2003 SP2, Windows Vista SP1 및 SP2, Windows Server 2008 Gold, SP2 및 R2, Windows 7의 win32k.sys에 있는 RtlQueryRegistryValues 함수의 스택 기반 버퍼 오버플로로 인해, 로컬 사용자가 SystemDefaultEUDCFont 레지스트리 키의 조작된 REG_BINARY 값을 통해 권한을 획득하고 User Account Control(UAC) 기능을 우회할 수 있다. 이는 "Driver Improper Interaction with Windows Kernel Vulnerability"라고도 한다.
Microsoft Windows XP SP2 및 SP3, Windows Server 2003 SP2, Windows Vista SP1 및 SP2, Windows Server 2008 Gold, SP2 및 R2, Windows 7의 win32k.sys에 있는 RtlQueryRegistryValues 함수의 스택 기반 버퍼 오버플로로 인해, 로컬 사용자가 SystemDefaultEUDCFont 레지스트리 키의 조작된 REG_BINARY 값을 통해 권한을 획득하고 User Account Control(UAC) 기능을 우회할 수 있다. 이는 "Driver Improper Interaction with Windows Kernel Vulnerability"라고도 한다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."