Monday, January 08, 2007 9:02 AM cmosby

Symantec Security Response Weblog: The CSRSS Bug and Vista

The CSRSS Bug and Vista

With the public advisory by Determina about a double-free bug in a CSRSS message function, the immediate question was: does it really affect Vista? The short answer is "yes, but not reliably." Arbitrary code execution is possible, but requires a great deal of luck, though a denial-of-service is definitely possible.

Why the fuss? Simply put, successful exploitation of the bug allows even the most restricted user-mode application to elevate its privileges to the System level. From there, the kernel is accessible even on Vista. Even without entering the kernel, System-level privileges allow almost complete control of the system, so the possibilities are limited only by the imagination.

Of course, that the bug isn't reliable on Vista doesn't mean that everyone can relax. The bug does affect earlier versions of Windows, where arbitrary code execution is far easier to achieve. Is it likely to be exploited? Oh yes. Not such a happy New Year.

Posted by Peter Ferrie on January 5, 2007 06:45 AM

Symantec Security Response Weblog: The CSRSS Bug and Vista.

Filed under: , ,

Comments

No Comments