
=====================================================================

                                CERT-Renater

                      Note d'Information No. 2012/VULN118
____________________________________________________________________

DATE                : 14/03/2012

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S) : Windows versions 7, XP, Server 2003, Vista,
                       Server 2008 running Windows Kernel-Mode Drivers.

======================================================================
KB2641653
http://technet.microsoft.com/en-us/security/bulletin/ms12-018
_______________________________________________________________________


Microsoft Security Bulletin MS12-018 - Important Vulnerability in
Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2641653)

   Published: Tuesday, March 13, 2012

   Version: 1.0

General Information

Executive Summary

   This security update resolves a privately reported vulnerability in
   Microsoft Windows. The vulnerability could allow elevation of privilege
   if an attacker logs on to a system and runs a specially crafted
   application. An attacker must have valid logon credentials and be able
   to log on locally to exploit this vulnerability.

   This security update is rated Important for all supported releases of
   Microsoft Windows. For more information, see the subsection, Affected
   Software, in this section.

Affected Software
   Windows XP Service Pack 3
   Windows XP Professional x64 Edition Service Pack 2
   Windows Server 2003 Service Pack 2
   Windows Server 2003 x64 Edition Service Pack 2
   Windows Server 2003 with SP2 for Itanium-based Systems
   Windows Vista Service Pack 2
   Windows Vista x64 Edition Service Pack 2
   Windows Server 2008 for 32-bit Systems Service Pack 2
   Windows Server 2008 for x64-based Systems Service Pack 2
   Windows Server 2008 for Itanium-based Systems Service Pack 2
   Windows 7 for 32-bit Systems
   Windows 7 for 32-bit Systems Service Pack 1
   Windows 7 for x64-based Systems
   Windows 7 for x64-based Systems Service Pack 1
   Windows Server 2008 R2 for x64-based Systems
   Windows Server 2008 R2 for x64-based Systems Service Pack 1
   Windows Server 2008 R2 for Itanium-based Systems
   Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Vulnerability Information

PostMessage Function Vulnerability - CVE-2012-0157

   An elevation of privilege vulnerability exists in the way that the
   Windows kernel-mode driver manages the PostMessage function. An
   attacker who successfully exploited this vulnerability could run
   arbitrary code in kernel mode. An attacker could then install programs;
   view, change, or delete data; or create new accounts with full
   administrative rights.


======================================================================

=========================================================
Les serveurs de référence du CERT-Renater
http://www.cru.fr/securite
http://www.renater.fr
=========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44          +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
+ 75013 Paris           | email: certsvp@renater.fr     +
=========================================================
