Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Check Point Update Service

Breaking News

01-Sep-2010: The Check Point IPS Research team has discovered a vulnerability in the CoreGraphics framework used by Mac OS X to render PDF files. A maliciously crafted PDF can cause an unexpected application termination or arbitrary code execution, allowing an attacker to take complete control of the affected system. The Check Point R70/71 IPS Software Blade provides protection against this flaw for unpatched systems.

Top Protections

Check Point Update Services Overview

In a constantly changing threat environment, defenses must evolve with or ahead of threats. Check Point Update Services provide real-time defense updates and configuration advice for IPS, URL Filtering, Antivirus & Anti-Malware, Anti-Spam & Email Security Security Service Software Blades. Also covered by Update Services are SmartDefense in NGX VPN-1, VSX, IPS-1, Connectra, Endpoint Security On Demand, and Endpoint Security products.

Key Benefits

  • Pre-emptive Protection - Keep your defenses current between your regularly-scheduled product upgrades and security patches.
  • Easy Management - Update your whole system in minutes. Each update comes with full configuration instructions and information about the associated threat.
  • IPS, Web security, Antivirus, Anti-Malware, Web filtering, and Anti-Spam protection - Get the latest signatures and detection methods.
  • Program Advisor - Update Check Point Endpoint Security with recommendations for application control for your endpoint computers.
  • 24x7 Threat Coverage - Check Point Security products are supported by multiple Check Point Research and Response Centers around the globe.

Latest Protections

Severity Date Check Point
Reference
Industry
Reference
Description
CPAI-2010-259   Update Protection against Symantec Alert Management System HNDLRSVC Arbitrary Command Execution Vulnerability
CPAI-2010-258 CVE-2010-2755 Update Protection against Mozilla Firefox Plugin Parameter Array Dangling Pointer Vulnerability
CPAI-2010-257 CVE-2010-0899 Update Protection against Oracle Secure Backup Administration property_box.php Command Injection Vulnerability
CPAI-2010-256 CVE-2010-1799 Update Protection against Apple QuickTime Streaming Debug Error Logging Buffer Overflow Vulnerability
CPAI-2010-255 CVE-2010-1801 Preemptive Protection against Apple Mac OS X CoreGraphics Heap Overflow Vulnerability
CPAI-2010-254 CVE-2010-2882 Update Protection against Adobe Shockwave Player rcsL Chunk Symbol Access Violations Vulnerability (APSB10-20)
CPAI-2010-253 CVE-2010-2864
CVE-2010-2881
Update Protection against Adobe Shockwave Player MCsL Parsing Memory Corruption Vulnerabilities (APSB10-20)
CPAI-2010-252 CVE-2010-2868 Update Protection against Adobe Shockwave Player CASt Parsing Memory Corruption Vulnerability (APSB10-20)
CPAI-2010-251 CVE-2010-2869 Update Protection against Adobe Shockwave Player IML32.dll XtcL Denial of Service Vulnerability (APSB10-20)
CPAI-2010-250 CVE-2010-2870 Update Protection against Adobe Shockwave Player MMAP Size Memory Corruption Vulnerability (APSB10-20)
CPAI-2010-249 CVE-2010-2880 Update Protection against Adobe Shockwave Player MMAP Index Memory Corruption Vulnerability (APSB10-20)
CPAI-2010-248 CVE-2010-2864 Update Protection against Adobe Shockwave Player IML32.dll Memory Corruption Vulnerability (APSB10-20)
CPAI-2010-245 CVE-2010-2865 Update Protection against Adobe Shockwave Player DIRAPI.dll Denial of Service Vulnerability (APSB10-20)
CPAI-2010-244 CVE-2010-2867 Update Protection against Adobe Shockwave Player rcsL Chunk Pointer Offset Heap Overflow Vulnerability (APSB10-20)
CPAI-2010-145

N/A

Preemptive Protection against Novell GroupWise Internet Agent IMAP Service Stack Buffer Overflow
CPAI-2010-144 CVE-2010-2703 Preemptive Protection against HP OpenView Network Node Manager webappmon.exe execvp_nc Buffer Overflow

Updated
CPAI-2010-247 CVE-2010-2862 Update Protection against Adobe Reader and Acrobat cooltype.dll Remote Code Execution Vulnerability (APSB10-17)
CPAI-2010-246 CVE-2010-0904 Update Protection against Oracle Secure Backup Administration Server Authentication Bypass Vulnerability
CPAI-2010-243 CVE-2010-1900 Update Protection Microsoft Word sprmCMajority Record Parsing Remote Code Execution (MS10-056)

Updated
CPAI-2010-242 CVE-2010-2564 Update Protection against Microsoft Windows Movie Maker Memory Corruption Vulnerability (MS10-050)

Updated
CPAI-2010-241 CVE-2010-1882 Update Protection against Microsoft MPEG Layer-3 Codecs Memory Corruption Vulnerability (MS10-052)

Updated
CPAI-2010-240 CVE-2010-2552 Update Protection against Microsoft SMB Stack Exhaustion Denial of Service Vulnerability (MS10-054)

Updated
CPAI-2010-239 CVE-2010-2561 Update Protection against Microsoft Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability (MS10-051)
CPAI-2010-238 CVE-2010-2558 Update Protection against Microsoft Internet Explorer Refresh Race Condition Memory Corruption Vulnerability (MS10-053)

Updated
CPAI-2010-237 CVE-2010-1902 Update Protection against Microsoft Word RTF Data Parsing Buffer Overflow Vulnerability (MS10-056)

Updated
CPAI-2010-236 CVE-2010-1901 Update Protection against Microsoft Word RTF Parsing Engine Memory Corruption Vulnerability (MS10-056)

Updated
CPAI-2010-235 CVE-2010-2551 Update Protection against Microsoft SMB Server Variable Validation Denial of Service Vulnerability (MS10-054)

Updated
CPAI-2010-234 CVE-2010-2550 Update Protection against Microsoft SMB Server Pool Overflow Remote Code Execution Vulnerability (MS10-054)

Updated
CPAI-2010-233 CVE-2010-2557 Update Protection against Microsoft Internet Explorer boundElements Uninitialized Memory Corruption Vulnerability (MS10-053)

Updated
CPAI-2010-232 CVE-2010-2556 Update Protection against Microsoft Internet Explorer Location Uninitialized Memory Corruption Vulnerability (MS10-053)

Archives

Best practices

Severity Date Check Point
Reference
Industry
Reference
Description
SBP-2010-24 CVE-2010-0542 Security Best Practice: Suspicious Characters in FTP User Name

Updated
SBP-2010-23 CVE-2009-0658
CVE-2009-1858
CVE-2010-1801
Security Best Practice: Protect Yourself from PDF Files Containing Malformed JBIG2 Structure Vulnerabilities
SBP-2010-22 CVE-2010-1297
CVE-2010-2168
CVE-2010-2201
Security Best Practice: Protect Yourself from PDF Files Containing Embedded Adobe Flash Movies Vulnerabilities (APSB10-15)
SBP-2010-21   Security Best Practice: Suspicious Adobe Director Files
SBP-2010-20   Security Best Practice: Familiarize Yourself with the SMB Remote Disk Scanning for Executable Files Protection
SBP-2010-19 CVE-2010-0127
CVE-2010-0128
CVE-2010-0129
CVE-2010-0130
CVE-2010-0986
CVE-2010-0987
CVE-2010-1280
CVE-2010-1281
CVE-2010-1282
CVE-2010-1283
CVE-2010-1284
CVE-2010-1286
CVE-2010-1287
CVE-2010-1288
CVE-2010-1289
CVE-2010-1290
CVE-2010-1291
CVE-2010-1292
Security Best Practice: Protect Yourself from Multiple Adobe Shockwave Player and Adobe Director Vulnerabilities (APSB10-12)
SBP-2010-18   Security Best Practice: Protect Yourself from Cross-Site Scripting Attacks
SBP-2010-17 CVE-2010-0812 Workaround for Microsoft Windows ISATAP IPv6 Source Address Spoofing Vulnerability (MS10-029)

Updated
SBP-2010-16 CVE-2010-0024 Security Best Practice: Blocking Null Prefix in DNS MX Records

Updated
SBP-2010-15 CVE-2010-0268 Workaround for Microsoft Windows Media Player ActiveX Codec Retrieval Vulnerability (MS10-027)
SBP-2010-14 CVE-2010-0254
CVE-2010-0256
CVE-2010-0095
CVE-2010-0096
CVE-2010-0097
Workaround for Multiple Microsoft Visio Memory Corruption Vulnerabilities (MS10-028)
SBP-2010-13   Security Best Practice: Blocking Legacy Browsers
SBP-2010-12   Security Best Practice: Blocking Internet Explorer 6
SBP-2010-11 CVE-2010-0232 Workaround for Microsoft Windows Kernel Exception Handler Code Execution Vulnerability (MS10-015)
SBP-2010-10   Security Best Practice: Protect Yourself from Pushdo Denial of Service Attacks
SBP-2010-09 CVE-2006-3227 Security Best Practice: Protect Yourself from Microsoft Internet Explorer US-ASCII Charset Obfuscation Exploits
SBP-2010-08   Security Best Practice: Aggressive Aging
SBP-2008-15   Security Best Practice: SIP Protocol Enforcement
SBP-2010-07   Security Best Practice: Protect Yourself from Multiple IMAP Vulnerabilities
SBP-2010-06   Security Best Practice: Protect Yourself from Multiple SMTP Vulnerabilities
SBP-2010-05   Security Best Practice: Protect Yourself from Multiple POP3 Vulnerabilities
SBP-2010-04 CVE-2009-3956 Security Best Practice: Blocking FDF Files Containing Timed Javascript
SBP-2010-03 CVE-2010-0018 Workaround for Microsoft Embedded OpenType Font Heap Overflow Vulnerability (MS10-001)
SBP-2010-02   Security Best Practice: Blocking ICQ
SBP-2010-01   Security Best Practice: Blocking Yahoo! Messenger
SBP-2009-28   Security Best Practice: Protect Yourself from PDF Containing Obfuscated Name Objects and Obfuscated JavaScript Filter Name Exploits
SBP-2009-27   Security Best Practice: Blocking BitTorrent
SBP-2009-26   Security Best Practice: Blocking Gnutella
SBP-2009-25   Security Best Practice: Blocking eMule
SBP-2009-24   Security Best Practice: Blocking Kazaa

Archives

Microsoft Security Bulletins for

= Check Point has provided a protection to this bulletin

Microsoft Security Bulletin MS10-060:
Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution (2265906)

Severity: Critical

CVE-2010-0019: Microsoft Silverlight Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Silverlight handles pointers. The vulnerability could allow remote code execution if a user visit a specially crafted Web site that contains Silverlight content.

CVE-2010-1898: Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability

A remote code execution vulnerability exists in the Microsoft .NET Framework that can allow a specially crafted Microsoft .NET application or a specially crafted Silverlight application to access memory, leading to arbitrary unmanaged code execution.

Microsoft Security Bulletin MS10-059:
Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege (982799)

Severity: High

CVE-2010-2554: Tracing Registry Key ACL Vulnerability

An elevation of privilege vulnerability exists when Windows places incorrect access control lists (ACLs) on the registry keys for the Tracing Feature for Services. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-2555: Tracing Memory Corruption Vulnerability

An elevation of privilege vulnerability exists due to the way that the Tracing Feature for Services allocates memory when processing specially crafted long strings from the registry. An attacker who successfully exploited this vulnerability could run arbitrary code with system-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS10-058:
Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886)

Severity: High

CVE-2010-1892: IPv6 Memory Corruption Vulnerability

A denial of service vulnerability exists in TCP/IP processing in Microsoft Windows due to an error in the processing of specially crafted IPv6 packets with a malformed extension header. An attacker could exploit the vulnerability by sending the target system a small number of specially crafted packets, causing the affected system to stop responding.

CVE-2010-1893: Integer Overflow in Windows Networking Vulnerability â€

An elevation of privilege vulnerability exists in TCP/IP processing in Microsoft Windows due to an error in the processing of a specific input buffer. An attacker who successfully exploited this vulnerability could run arbitrary code with system-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS10-057:
Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707)

Severity: High

CVE-2010-2562: Excel Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS10-056:
Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)

Severity: Critical

CVE-2010-1900: Word Record Parsing Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office Word handles malformed records inside a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

CVE-2010-1901: Word RTF Parsing Engine Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office Word parses rich text data. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

CVE-2010-1902: Word RTF Parsing Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office Word parses certain rich text data. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

CVE-2010-1903: Word HTML Linked Objects Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office Word handles a specially crafted Word file that includes a malformed record. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Bulletin MS10-055:
Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665)

Severity: Critical

CVE-2010-2553: Cinepak Codec Decompression Vulnerability

A remote code execution vulnerability exists in the way the Cinepak codec handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted media file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Bulletin MS10-054:
Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214)

Severity: Critical

CVE-2010-2550: SMB Pool Overflow Vulnerability

An unauthenticated remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message to a computer running the Server service. An attacker who successfully exploited this vulnerability could take complete control of the system.

CVE-2010-2551: SMB Variable Validation Vulnerability

A denial of service vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB packets. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message to a computer running the Server service.

CVE-2010-2552: SMB Stack Exhaustion Vulnerability

A denial of service vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol software handles specially crafted SMB compounded requests. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted network message to a computer running the Server service.

Microsoft Security Bulletin MS10-053:
Cumulative Security Update for Internet Explorer (2183461)

Severity: Critical

CVE-2010-1258: Event Handler Cross-Domain Vulnerability

An information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow information disclosure if a user viewed the Web page and then interacts with the browser window using the mouse.

CVE-2010-2556: Uninitialized Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-2557: Uninitialized Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-2558: Race Condition Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that may have been corrupted due to a race condition. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-2559: Uninitialized Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-2560: HTML Layout Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS10-052:
Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (2115168)

Severity: Critical

CVE-2010-1882: MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft DirectShow MP3 filter handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted audio file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Bulletin MS10-051:
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2079403)

Severity: Critical

CVE-2010-2561: Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Microsoft XML Core Services handles HTTP responses. The vulnerability could allow remote code execution if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Bulletin MS10-050:
Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (981997)

Severity: High

CVE-2010-2564: Movie Maker Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that Windows Movie Maker handles specially crafted project files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS10-049:
Vulnerabilities in SChannel could allow Remote Code Execution (980436)

Severity: Critical

CVE-2009-3555: TLS/SSL Renegotiation Vulnerability

A spoofing vulnerability exists in the TLS/SSL protocol, implemented in the Microsoft Windows SChannel authentication component. An attacker who successfully exploited this vulnerability would be able to introduce information on a TLS/SSL protected connection, effectively sending traffic spoofing the authenticated client. This security addresses a vulnerability previously discussed in Microsoft Security Advisory 977377.

CVE-2009-3555: TLS/SSL Renegotiation Vulnerability

A spoofing vulnerability exists in the TLS/SSL protocol, implemented in the Microsoft Windows SChannel authentication component. An attacker who successfully exploited this vulnerability would be able to introduce information on a TLS/SSL protected connection, effectively sending traffic spoofing the authenticated client. This security addresses a vulnerability previously discussed in Microsoft Security Advisory 977377.

CVE-2010-2566: SChannel Malformed Certificate Request Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that SChannel on a client machine validates a certificate request message sent by the server. An attacker could host a specially crafted Web site that is designed to exploit these vulnerabilities through an Internet Web browser and then convince a user to view the Web site. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or in an Instant Messenger message that takes users to the attackers Web site.

Microsoft Security Bulletin MS10-048:
Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2160329)

Severity: High

CVE-2010-1887: Win32k Bounds Checking Vulnerability

A denial of service vulnerability exists in the Windows kernel-mode drivers due to the improper validation of an argument passed to a system call. An attacker could exploit the vulnerability by running a specially crafted application causing the system to become unresponsive and automatically restart.

CVE-2010-1894: Win32k Exception Handling Vulnerability

An elevation of privilege vulnerability exists due to the way the Windows kernel-mode drivers handle certain exceptions. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-1895: Win32k Pool Overflow Vulnerability

An elevation of privilege vulnerability exists because the Windows kernel-mode drivers do not properly allocate memory when making a copy from user mode. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-1896: Win32k User Input Validation Vulnerability

An elevation of privilege vulnerability exists in Windows kernel-mode drivers due to improper validation of input passed from user mode. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-1897: Win32k Window Creation Vulnerability

An elevation of privilege vulnerability exists because Windows kernel-mode drivers do not properly validate all parameters when creating a new window. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS10-047:
Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852)

Severity: High

CVE-2010-1888: Windows Kernel Data Initialization Vulnerability

An elevation of privilege vulnerability exists in the Windows Kernel due to the way the kernel deals with specific thread creation attempts. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-1889: Windows Kernel Double Free Vulnerability

An elevation of privilege vulnerability exists in the Windows Kernel due to the way the kernel initializes objects while handling certain errors. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2010-1890: Windows Kernel Improper Validation Vulnerability

A denial of service vulnerability exists in the way that the Windows kernel validates access control lists on kernel objects. An attacker could exploit the vulnerability by running a specially crafted application causing the system to become unresponsive and automatically restart.

Microsoft Security Bulletin MS10-046:
Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198)

Severity: Critical

CVE-2010-2568: Shortcut Icon Loading Vulnerability

A remote code execution vulnerability exists in affected versions of Microsoft Windows. The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could run arbitrary code as the logged-on user. This update addresses a vulnerability previously discussed in Microsoft Security Advisory 2286198.