Lucene search

K
saintSAINT CorporationSAINT:585BD16E3B2DBE582DC4F6AE14C102F6
HistoryJan 14, 2011 - 12:00 a.m.

Windows Thumbnail View CreateSizedDIBSECTION buffer overflow

2011-01-1400:00:00
SAINT Corporation
download.saintcorporation.com
12

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.973

Percentile

99.9%

Added: 01/14/2011
CVE: CVE-2010-3970
BID: 45662
OSVDB: 70263

Background

The **shimgvw.dll** library is part of the Microsoft Graphics Rendering Engine.

Problem

A vulnerability in **shimgvw.dll** allows command execution when Windows renders a thumbnail image which passes a specially crafted **biClrUsed** parameter to the **CreateSizedDIBSECTION** function.

Resolution

See Microsoft Security Advisory 2490606 for fix information or workarounds.

References

<http://www.kb.cert.org/vuls/id/106516&gt;

Limitations

Exploit works on Windows Explorer 5.1 on Windows XP.

Platforms

Windows XP

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.973

Percentile

99.9%