Privacy and Legal Notice

CIAC INFORMATION BULLETIN

S-258: Vulnerability in Windows Kernel

[Microsoft Security Bulletin (MS08-025)]

April 9, 2008 21:00 GMT
[REVISED 10 Apr 2008]
[REVISED 14 Apr 2008]
[REVISED 17 Apr 2008]

PROBLEM: An elevation of privilege vulnerability exists due to the Windows kernel improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges.
PLATFORM: Windows 2000 (all editions)
Windows XP (all editions)
Windows Server 2003 (all editons)
Windows Vista (all editions)
Windows Server 2008 (all editions)
Storage Management Appliance (SMA) v2.1 software running on Storage Management Appliance I, II, III
DAMAGE: Elevation of privilege.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is MEDIUM. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system.

CVSS 2 BASE SCORE:
   TEMPORAL SCORE:
   VECTOR:
5.2
4.3
(AV:L/AC:L/Au:S/C:C/I:P/A:N/E:F/RL:OF/RC:C)

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/s-258.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/security/Bulletin/MS08-025.mspx
  ADDITIONAL LINK: Visit Hewlett-Packars's Subscription Service for:
HPSBST02329 SSRT080048 rev. 1
  CVE: CVE-2008-1084

REVISION HISTORY:
04/10/2008 - revised S-258 to reflect changes Microsoft has made in MS08-025 where 
             they clarified the Known Issues section of the FAQ.
04/14/2008 - revised S-258 to reflect changes Microsoft has made in MS08-025 where 
             they clarified the systems at risk and removed a reference to unsupported
             software.
04/17/2008 - revised S-258 to add a link to link to Hewlett-Packard's Subscription 
             Service for HPSBST02329 SSRT080048 rev. 1 for Storage Management Appliance 
			 (SMA) v2.1 software running on Storage Management Appliance I, II, III.



[***** Start Microsoft Security Bulletin (MS08-025) *****]

Microsoft Security Bulletin MS08-025 – Important

Vulnerability in Windows Kernel Could Allow Elevation of Privilege (941693)

Published: April 8, 2008 | Updated: April 11, 2008

Version: 1.2

General Information

Executive Summary

This security update resolves a privately reported vulnerability in the Windows kernel. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.

This is an important security update for all supported editions of Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008. For more information, see the subsection, Affected and Non-Affected Software, in this section.

This security update addresses the vulnerability by modifying the way that the Windows kernel validates inputs passed from user mode. For more information about this vulnerability, see the Frequently Asked Questions (FAQ) subsection under the next section, Vulnerability Information.

Recommendation.  Microsoft recommends that customers apply the update at the earliest opportunity.

Known Issues. Microsoft Knowledge Base Article 941693 documents the currently known issues that customers may experience when they uninstall this security update.

Affected and Non-Affected Software

The following software have been tested to determine which versions or editions are affected. Other versions or editions are either past their support life cycle or are not affected. To determine the support life cycle for your software version or edition, visit Microsoft Support Lifecycle.

Affected Software

Operating System Maximum Security Impact Aggregate Severity Rating Bulletins Replaced by this Update

Microsoft Windows 2000 Service Pack 4

Elevation of Privilege

Important

None

Windows XP Service Pack 2

Elevation of Privilege

Important

None

Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2

Elevation of Privilege

Important

None

Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2

Elevation of Privilege

Important

None

Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2

Elevation of Privilege

Important

None

Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium based Systems

Elevation of Privilege

Important

None

Windows Vista and Windows Vista Service Pack 1

Elevation of Privilege

Important

None

Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1

Elevation of Privilege

Important

None

Windows Server 2008 for 32-bit Systems

Elevation of Privilege

Important

None

Windows Server 2008 for x64-based Systems

Elevation of Privilege

Important

None

Windows Server 2008 for Itanium-based Systems

Elevation of Privilege

Important

None

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Information

Severity Ratings and Vulnerability Identifiers

Windows Kernel Vulnerability - CVE-2008-1084

Update Information

Detection and Deployment Tools and Guidance

Security Update Deployment