Windows Zero-Day Vulnerability Researched by Microsoft
An unnamed security researcher released information Monday on a discovered Windows vulnerability that could be used to perform remote code execution. Along with bringing the hole to the attention of Microsoft, the researcher posted the proof-of-concept exploit code that triggers a blue-screen PC system freeze.
The vulnerability affects all versions of Windows, with Microsoft cautioning that system servers running as the primary domain controller may be at highest risk, according to the researcher, identified only by the user name "Cupidon-3005."
In a TechNet blog, Matt Oh, member of the MMPC Vulnerability Response Team, provided some more details on the situation: "...the vulnerability is inside an error-reporting function of the CIFS browser service module. The function gets a variable number of arguments as parameters. Those string arguments are pushed on the stack for processing. In some cases, some of the strings can be controlled by the attacker."