Microsoft Windows Knowledge Base Article 977165 update is not installed (WinMs10kb977165Update)

Vuln ID: 55921
Risk Level: High risk vulnerability  High WinMs10kb977165Update
Platforms: Microsoft Windows 2000: SP4, Microsoft Windows XP: SP2, Microsoft Windows Vista, Microsoft Windows Server 2003: SP2, Microsoft Windows Server 2003: SP2 Itanium, Microsoft Windows Server 2003: SP2 x64, Microsoft Windows Vista: x64, Microsoft Windows XP: SP2 x64 Professional, Microsoft Windows Vista: SP1, Microsoft Windows Vista: SP1 x64, Microsoft Windows Server 2008: Itanium, Microsoft Windows Server 2008: x32, Microsoft Windows Server 2008: x64, Microsoft Windows XP: SP3, Microsoft Windows Vista: SP2 x64, Microsoft Windows Vista: SP2, Microsoft Windows Server 2008: SP2 x32, Microsoft Windows Server 2008: SP2 x64, Microsoft Windows 7: x32, Microsoft Windows Server 2008, Microsoft Windows Server 2008: SP2, Microsoft Windows Server 2008: SP2 Itanium
Description:

Microsoft Windows Knowledge Base Article 977165 update is not installed on the system, which could allow an attacker to exploit the following vulnerabilities:

Microsoft Windows could allow a local attacker to gain elevated privileges on the system, caused by an error in the #GP trap handler when setting up a VDM context. By setting up a specially-crafted VDM_TIB in their TEB using the #GP trap handler (nt!KiTrap0D), a local attacker could exploit this vulnerability to execute arbitrary code on the system with kernel privileges.

Microsoft Windows could allow a local attacker to gain elevated privileges on the system, caused by the improper resetting of a pointer when memory is released. A local authenticated attacker could exploit this vulnerability to trigger a double free condition and execute arbitrary code on the system with kernel privileges.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS10-015. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS10-015
Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)
http://www.microsoft.com/technet/security/bulletin/ms10-015.mspx

IBM Internet Security Systems X-Force Database
Microsoft Windows #GP trap handler privilege escalation
http://xforce.iss.net/xforce/xfdb/55742

IBM Internet Security Systems X-Force Database
Microsoft Windows kernel privilege escalation
http://xforce.iss.net/xforce/xfdb/55920

ISS X-Force
Microsoft Windows Knowledge Base Article 977165 update is not installed
http://www.iss.net/security_center/static/55921.php

CVE CVE-2010-0233
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0233

CVE CVE-2010-0232
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0232


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures