vendor:
Windows XP
by:
Oleksiuk Dmytro (aka Cr4sh)
7,2
CVSS
HIGH
Local Privileges Escalation
119
CWE
Product Name: Windows XP
Affected Version From: Windows XP SP3
Affected Version To: Windows XP SP3
Patch Exists: YES
Related CWE: CVE-2012-0183
CPE: o:microsoft:windows_xp
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Windows XP keyboard layouts pool corruption 0day PoC, post-MS12-034
Vulnerability exists in the function win32k!ReadLayoutFile(), that parses keyboard layout files data. Possible attack vector -- local privileges escalation. Similar vuln (CVE-2012-0183) was patched recently, but Microsoft missed to rewrite vulnerable code on Windows XP, and this PoC still able to crash fully-patched XP SP3. However, pool corruption is not fully-controllable, and reliable code execution exploit development is quite a difficult task.
Mitigation:
Apply the latest security patches from Microsoft