Skip to main content

Microsoft Windows Tracing Feature for Services Multiple Vulnerabilities ( 11 August 2010 )

Last Update Date: 28 Jan 2011 Release Date: 11 Aug 2010 4485 Views

RISK: Medium Risk

1. Tracing Registry Key ACL Vulnerability

An elevation of privilege vulnerability exists when Windows places incorrect access control lists (ACLs) on the registry keys for the Tracing Feature for Services. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

2. Tracing Memory Corruption Vulnerability

An elevation of privilege vulnerability exists due to the way that the Tracing Feature for Services allocates memory when processing specially crafted long strings from the registry. An attacker who successfully exploited this vulnerability could run arbitrary code with system-level privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.