Easy privilege escalation in Metasploit using Tavis Ormandy's KiTrap0d code (with minor tweaks): http://pastie.org/793713 (svn update)-----------------------------
Original advisory - http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html
If the use of 16-bit program is not required, you can disable the VDM by a simple registry configuration change. This mitigation is outlined in an H-Online article from last week.
-----------------------------
On Jan 20th, Microsoft released a Security Advisory (979682) outlining the issue....
http://www.microsoft.com/technet/security/advisory/979682.mspx
No comments:
Post a Comment