- Servers
- Desktops
- Laptops
- Tablet PCs
- PDAs
- Smart phones
- Digital cameras
- Camcorders
- Printers & multifunction devices
- Scanners
- Copiers
- Monitors & projectors
- Hard drives & burners
- Peripherals
- Productivity
- Accounting & finance
- Data management
- Graphics & publishing
- Web publishing
- Operating systems
- Security & utilities
- Downloads & trial software
- Handheld software
- Instant messaging
- Cell phones & plans
- Voice over Internet
- Telephones
- Routers & gateways
- Wireless networking
- Network adapters
- Internet access
- Web hosting
- Domain search
- Hotspot Zone
- Desktops
- Laptops
- Servers and storage
- PDAs
- Cell phones
- Monitors & projectors
- Printers
- Networking and wireless
- Security and utility software
- Productivity software
- Access, hosting, and services
- All business buying guides
CNET Security Center: Your complete source of antivirus and Internet security information.
Windows flaw in WINSRV.DLL CVE-2006-6696
A serious flaw in Windows provides privilege escalation for local users.
By Robert Vamosi (March 12, 2007)
There's a flaw within Microsoft Windows 2000, XP, 2003, and Vista that allows local users to gain privileges by calling the MessageBox function with a specialized message. A specially crafted MB_SERVICE_NOTIFICATION designed to send a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process may not be properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
A serious flaw in Windows provides privilege escalation for local users.
By Robert Vamosi (March 12, 2007)
QUICK FACTS
Name: Windows flaw in WINSRV.DLL
Date first reported: 11/08/06
Vulnerable software: Microsoft Windows 2000, XP, 2003, and Vista
What it does: Provides privilege escalation for local users.
Recommendations: None
Exploit code available: No
Vendor patch available: No
Date first reported: 11/08/06
Vulnerable software: Microsoft Windows 2000, XP, 2003, and Vista
What it does: Provides privilege escalation for local users.
Recommendations: None
Exploit code available: No
Vendor patch available: No
Additional Resources:
Microsoft: Technical advisory
Milw0rm: 2967
Frsirt: 5120
Secunia: 2344
