Windows VDM #UD Local Privilege Escalation
Release Date:
October 12, 2004
Date Reported:
March 18, 2004
Severity:
Medium (Local Privilege Escalation to Kernel)
[NOTE: This vulnerability was silently fixed by Microsoft in June,
approximately 90 days after it was reported, with the release of Windows
XP SP2 Release Candidate 2. All other versions of Windows remained
unpatched for over 120 additional days.]
Since this advisory is really dry and jargony, we have to throw in
something a little off-beat. We leave you with this:
T: Hey man, what're you reading?
N: Listen to this -- it's an advisory written by eEye in the
first-person. I am Jack's LDT; without me, Jack could not emulate his
legacy DOS applications like Doom on NT.
N: There's a whole series of these: I am Jill's null pointer. I am
Jack's kernel--
T: Yeah, I get exploited, I completely compromise Jack in such a way
that necessitates a total system reinstallation.
Hope that clears things up. (With apologies to Chuck Palahniuk.)