Free hard drive encryption - Download a trial of SafeGuard Easy
Vulnerability: MS09-006. Critical Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690)
Back to Latest vulnerabilities homepage
Click any highlighted term for further explanation.
| Details | |
|---|---|
| Vulnerability name/brief description | Critical Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690) - MS09-006. |
| CVE/CAN name | CVE-2009-0081 CVE-2009-0082 CVE-2009-0083 |
| Vendor threat level | Critical |
| SophosLabs threat level | High |
| Solution | Users are advised to apply the vendor patch for MS09-006 . |
| Vendor description | This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system. |
| SophosLabs comments | The patched vulnerabilities may result in remote code execution. They can be exploited by simply viewing specifically crafted web pages and so the vulnerability is assigned a high threat level. |
| SophosLabs testing result | N/A |
| Currently known exploits | At the time of writing SophosLabs has seen no samples of malware or web-content attempting to exploit this vulnerability. Should this situation change samples will be analyzed and we will take action as necessary. |
| First sample seen | N/A |
| Discovery date | March 10, 2009 |
| Affected software | Microsoft Windows 2000 Service Pack 4 Windows XP Service Pack 2 and Windows XP Service Pack 3 Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems Windows Vista and Windows Vista Service Pack 1 Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 Windows Server 2008 for 32-bit Systems Windows Server 2008 for x64-based Systems Windows Server 2008 for Itanium-based Systems |
| References | http://www.microsoft.com/technet/security/bulletin/ms09-006.mspx |
| Credits | Microsoft |
| Revisions |
Explanation of terms
Vulnerability Name/Brief Description:
Vendor identifier plus a brief description of the type of attack.
CVE/CAN Name:
Currently assigned CVE name. If a CVE name doesn't exist the CAN name will be used until a CVE has been assigned.
Vendor Threat Level:
Threat level assigned by the vendor
SophosLabs Threat Level:
Threat level assigned by SophosLabs
- LOW RISK - There is little chance of this vulnerability being actively exploited by malware.
- MEDIUM RISK - There is a possibility of this vulnerability being actively exploited by malware.
- HIGH RISK - There is a strong possibility of this vulnerability being actively exploited by malware.
- CRITICAL RISK - This vulnerability will almost certainly be actively exploited by malware.
Solution:
Vendor-supplied Patch identifier and recommended solution, or workaround if applicable.
Vendor Description:
Summary of the cause and potential effect of the vulnerability provided by the vendor.
SophosLabs Comments:
SophosLabs' opinions and observations of the vulnerability in question.
SophosLabs Testing Result:
Details of completed lab testing, if applicable. Please note that the lab test environment may differ significantly from user environments.
Currently Known Exploits:
List of identities for known exploits, if applicable.
First Sample Seen:
Date of the first sample seen by SophosLabs.
Discovery Date:
Date of the earliest known publically disclosed advisory.
Affected Software:
Vulnerable platforms and software versions.
If you need more information or guidance, then please contact technical support.
- Article ID: 43573
- Created: 13 Aug 2008
- Last updated: 11 Mar 2009
- Protect sensitive data from unauthorized use
- Encrypt data, hard drives and removable media
- Work uninterrupted with encryption on demand

