This application requires Javascript for optimal performance.

MS.Windows7.64bit.Memory.Corruption

Release Date

Jan 12, 2012

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

This indicates an attack attempt to exploit a Memory Corruption vulnerability in Microsoft Windows 7 64bit.

The vulnerability is caused due to an error in win32k.sys when handling a maliciously crafted webpage. As a result, an attacker can trick an unsuspecting into visiting a malicious webpage and execute arbitrary code within the context of the application or possibly cause a denial of service condition.

Affected Products

Microsoft Windows 7 64bit

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://technet.microsoft.com/en-us/security/bulletin/MS12-008

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-5046

Reference/s

http://www.securityfocus.com/bid/51122 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/MS12-008.mspx (MS-ID)
http://www.exploit-db.com/exploits/18275/
http://isc.sans.org/diary/New+Vulnerability+in+Windows+7+64+bit/12238
https://secunia.com/advisories/47237/

Reference: VID-30682