Microsoft Management Console File Format Denial of Service Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A denial of service vulnerability exists when Windows attempts to access a specially crafted .msc file to retrieve the icon information, and then fails to properly validate a destination buffer, resulting in a denial of service. An unauthenticated attacker could exploit this vulnerability by convincing a user to open a share containing a specially crafted .msc file. However, the attacker has no means to force a user to visit the share or view the file.
Impact
- Denial of Service
System / Technologies affected
- Microsoft Windows Vista
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows Server 2008 R2
- Microsoft Windows 8 and Windows 8.1
- Microsoft Windows RT and Windows RT 8.1
- Microsoft Windows Server 2012 and Windows Server 2012 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-054
Vulnerability Identifier
Source
Related Link
Share with