Skip to main content

Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 28 Dec 2010 5847 Views

RISK: Medium Risk

A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to execute arbitrary code. This issue is caused by a buffer overflow error in the Fax Cover Page Editor (fxscover.exe) utility when processing a cover file ".cov" containing malformed data, which could be exploited by attackers to crash an affected application or compromise a vulnerable system by tricking a user into opening a malicious cover file via a vulnerable application.

The Fax Cover Page Editor (fxscover.exe) utility is installed with the "Fax Services" on Windows XP and Windows Server 2003 and is available via the "Windows Fax and Scan" program on Windows Vista, Windows Server 2008, and Windows 7.

It has been confirmed this vulnerability with Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP 2 Ultimate, and Windows 7 Ultimate.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Windows 7
  • Microsoft Windows Server 2008 Service Pack 2
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Vista Service Pack 2
  • Microsoft Windows Server 2003 Service Pack 2
  • Microsoft Windows XP Service Pack 3

Solutions

It is not aware of any vendor-supplied patch.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link