Monday, December 27, 2010

Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability

http://www.vupen.com/english/advisories/2010/3327

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the Fax Cover Page Editor (fxscover.exe) utility when processing a cover file ".cov" containing malformed data, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by tricking a user into opening a malicious cover file via a vulnerable application.

The Fax Cover Page Editor (fxscover.exe) utility is installed with the "Fax Services" on Windows XP and Windows Server 2003 (disabled by default) and is available via the "Windows Fax and Scan" program on Windows Vista, Windows Server 2008, and Windows 7 (enabled by default).

VUPEN has confirmed this vulnerability with Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows 7 Ultimate.

No comments:

Post a Comment