Nortel Response to Microsoft Security Bulletin MS09-006 - Vulnerabilities in Windows Kernel
| Description: |
On Tuesday, March 10th, Microsoft released MS09-006 - Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690). This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. MS09-006 addresses the following CVEs: 1) Windows Kernel Input Validation Vulnerability - CVE-2009-0081 - (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0081) A remote code execution vulnerability exists in the Windows kernel due to improper validation of input passed from user mode through the kernel component of GDI. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 2) Windows Kernel Handle Validation Vulnerability - CVE-2009-0082 - (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0082) An elevation of privilege vulnerability exists in the Windows kernel due to the manner in which the kernel validates handles. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 3) Windows Kernel Invalid Pointer Vulnerability - CVE-2009-0083 - (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0083) An elevation of privilege vulnerability exists in the Windows kernel due to improper handling of a specially crafted invalid pointer. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user ri |
| Type: |
Security Advisories |
| Number: |
2009009381, Rev 1 |
| Status: |
Retired |
| Date: |
2009-09-29 |