Click any highlighted term for further explanation. For more information, contact technical support.
|
|
Details
|
|
Vulnerability name/brief description
|
MS12-054 - Vulnerabilities in Windows Networking Components Could Allow Remote Code Execution
|
|
CVE/CAN name
|
|
|
Vendor threat level
|
Critical
|
|
SophosLabs threat level
|
High
|
|
Solution
|
MS12-054
|
|
Vendor description
|
This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker sends a specially crafted response to a Windows print spooler request.
|
|
SophosLabs comments
|
These vulnerabilities can cause remote code execution on Windows XP and Windows Server 2003 platforms and denial of service on other affected Windows platforms. SophosLabs rate this as High.
|
|
SophosLabs testing result
|
No SophosLabs testing result found
|
|
Currently known exploits
|
No currently known exploits found
|
|
First sample seen
|
No samples found
|
|
Discovery date
|
14 Aug 2012
|
|
Affected software
|
Windows XP Service Pack 3 (KB2705219)
Windows XP Service Pack 3 (KB2712808)
Windows XP Professional x64 Edition Service Pack 2 (KB2705219)
Windows XP Professional x64 Edition Service Pack 2 (KB2712808)
Windows Server 2003 Service Pack 2
(KB2705219)
Windows Server 2003 Service Pack 2 (KB2712808)
Windows Server 2003 x64 Edition Service Pack 2 (KB2705219)
Windows Server 2003 x64 Edition Service Pack 2 (KB2712808)
Windows Server 2003 with SP2 for Itanium-based Systems (KB2705219)
Windows Server 2003 with SP2 for Itanium-based Systems (KB2712808)
Windows Vista Service Pack 2 (KB2705219)
Windows Vista Service Pack 2 (KB2712808)
Windows Vista x64 Edition Service Pack 2 (KB2705219)
Windows Vista x64 Edition Service Pack 2 (KB2712808)
Windows Server 2008 for 32-bit Systems Service Pack 2 (KB2705219)
Windows Server 2008 for 32-bit Systems Service Pack 2 (KB2712808)
Windows Server 2008 for x64-based Systems Service Pack 2 (KB2705219)
Windows Server 2008 for x64-based Systems Service Pack 2 (KB2712808)
Windows Server 2008 for Itanium-based Systems Service Pack 2 (KB2705219)
Windows Server 2008 for Itanium-based Systems Service Pack 2 (KB2712808)
Windows 7 for 32-bit Systems (KB2705219)
Windows 7 for 32-bit Systems (KB2712808)
Windows 7 for 32-bit Systems Service Pack 1 (KB2705219)
Windows 7 for 32-bit Systems Service Pack 1 (KB2712808)
Windows 7 for x64-based Systems (KB2705219)
Windows 7 for x64-based Systems (KB2712808)
Windows 7 for x64-based Systems Service Pack 1 (KB2705219)
Windows 7 for x64-based Systems Service Pack 1 (KB2712808)
Windows Server 2008 R2 for x64-based Systems (KB2705219)
Windows Server 2008 R2 for x64-based Systems (KB2712808)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB2705219)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB2712808)
Windows Server 2008 R2 for Itanium-based Systems (KB2705219)
Windows Server 2008 R2 for Itanium-based Systems (KB2712808)
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (KB2705219)
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (KB2712808)
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB2705219)
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (KB2712808)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB2705219)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) (KB2712808)
Windows Server 2008 R2 for x64-based Systems (Server Core installation)
(KB2705219)
Windows Server 2008 R2 for x64-based Systems (Server Core installation) (KB2712808)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB2705219)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (KB2712808)
|
|
References
|
|
|
Credits
|
|
|
Revisions
|
-
August 14, 2012 - Initial analysis written
|
Explanation of terms
Vulnerability Name/Brief Description:
Vendor identifier plus a brief description of the type of attack.
CVE/CAN Name:
Currently assigned CVE name. If a CVE name doesn't exist the CAN name will be used until a CVE has been assigned.
Vendor Threat Level:
Threat level assigned by the vendor
SophosLabs Threat Level:
Threat level assigned by SophosLabs
- LOW RISK - There is little chance of this vulnerability being actively exploited by malware.
- MEDIUM RISK - There is a possibility of this vulnerability being actively exploited by malware.
- HIGH RISK - There is a strong possibility of this vulnerability being actively exploited by malware.
- CRITICAL RISK - This vulnerability will almost certainly be actively exploited by malware.
Solution:
Vendor-supplied Patch identifier and recommended solution, or workaround if applicable.
Vendor Description:
Summary of the cause and potential effect of the vulnerability provided by the vendor.
SophosLabs Comments:
SophosLabs' opinions and observations of the vulnerability in question.
SophosLabs Testing Result:
Details of completed lab testing, if applicable. Please note that the lab test environment may differ significantly from user environments.
Currently Known Exploits:
List of identities for known exploits, if applicable.
First Sample Seen:
Date of the first sample seen by SophosLabs.
Discovery Date:
Date of the earliest known publically disclosed advisory.
Affected Software:
Vulnerable platforms and software versions.