Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Highly critical zero day vulnerability in Windows discovered (Safari)  (Read 1944 times)

AdrianH

  • Guest

http://www.h-online.com/security/news/item/Highly-critical-zero-day-vulnerability-in-Windows-discovered-1398625.html

Quote
Secunia has reported that an unpatched security vulnerability in the 64-bit version of Windows 7 may be able to be exploited to inject and execute malicious code; currently, the only known exploit causes the system to crash.

It is possible to trigger a memory error in the system file win32k.sys by accessing a crafted HTML file in Safari. webDEViL, who discovered the vulnerability, has published a proof of concept on Twitter. His demo simply consists of an IFrame with a specific height which when displayed in Safari results in a blue screen of death.

The possibility that the vulnerability can be exploited by using means other than Safari cannot be ruled out. According to webDEViL, the source of the vulnerability is the function NtGdiDrawStream. The H's associates at heise Security have been able to reproduce the problem. The 32-bit version is not affected. When and whether Microsoft will fix the vulnerability is not known.

Secunia's link >> http://secunia.com/advisories/47237/
Logged

tuftedduck

  • Senior Kitizen
  • ******
  • Posts: 29658
  • Router Luvvin Duck
Re: Highly critical zero day vulnerability in Windows discovered (Safari)
« Reply #1 on: December 21, 2011, 06:50:35 AM »

 :(
Logged

AdrianH

  • Guest
Re: Highly critical zero day vulnerability in Windows discovered (Safari)
« Reply #2 on: December 24, 2011, 09:21:25 AM »

Now confirmed as also affecting IE versions prior to IE9 , still only on 64bit systems at present, it is also suspected that other browsers may be an issue .................
Logged

BritBrat

  • Kitizen
  • ****
  • Posts: 1359
Re: Highly critical zero day vulnerability in Windows discovered (Safari)
« Reply #3 on: December 25, 2011, 09:18:01 AM »

Rather than spend money on Christmas cards I am donating to Julia's House Hospice for terminally ill children   JULIA'S HOUSE / DONATE

You may want to recheck link
http://www.juliashouse.org/Donate.aspx

JULIA'S HOUSE / DONATE
Code: [Select]
[url=http://www.juliashouse.org/Donate.aspx]JULIA'S HOUSE / DONATE[/url]
« Last Edit: December 25, 2011, 10:44:36 AM by BritBrat »
Logged
 

anything