61854 : Microsoft Windows #GP Trap Handler (nt!KiTrap0D) Local Privilege Escalation
Printer | http://osvdb.org/61854 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
10 1995 over 2 years ago about 1 year ago 11 times 25%

This Entry needs help! It is only 25% Complete. Click the edit link above to add more information.

Contributing is fast and easy, and benefits the entire security community.

Timeline

Disclosure Date Vendor Solution Date
2010-01-19 2010-01-19

Description

<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0232" target="_blank">CVE</a>)</em> : The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka &quot;Windows Kernel Exception Handler Vulnerability.&quot;

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Commercial
Disclosure: Vendor Verified

Products

Unknown or Incomplete

References

Tools & Filters

44425

Credit

Unknown or Incomplete

CVSSv2 Score

CVSSv2 Base Score = 6.6
Source: nvd.nist.gov | Generated: 2010-01-22 | Disagree? | There are 1 more: View All

Access_vector_0 Access_complexity_1 Authentication_1 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2010/02/18 21:14:32 | Windows Kernel Patch Hobbled by Malware

from: RedmondMag.com

...according to Microsoft, but 32-bit systems can be vulnerable. Microsoft suspended the automatic release of security bulletin MS10-015 through Windows Update but expects to resume delivery after further work. "Microsoft is striving to resolve the issue as quickly...

2010/02/18 13:37:15 | WinXP reboots caused when patch meets malware

from: Houston Chronicle

...an update on our ongoing investigation into the "blue screen" issues affecting a limited number of customers who installed MS10-015. We have been working around the clock with our customers, partners and several teams at Microsoft to determine the cause of...

2010/02/18 18:55:42 | Microsoft says rootkit caused Windows blue screens

from: NetworkWorld

Microsoft late on Wednesday confirmed that a rootkit caused Windows PCs to crash after users applied a security patch issued last week. Only systems infected with the Alureon rootkit were incapacitated with Blue Screen of Death (BSOD) errors that

2010/02/12 16:00:00 | Microsoft says malware causing blue screen crashes

from: NetworkWorld

A hard-to-detect rootkit may be causing Windows XP systems to crash following Microsoft's latest security updates. Windows users began flooding Windows support forums this week, saying that their computers had been rendered unusable with a

2010/02/15 17:08:19 | Restart issues after installing MS10-015? Microsoft wants your help!

from: ZDNet

One of the key components when investigating issues like this are obtaining memory dumps from computers experiencing the problem. In order to get the information we need to fully analyze the issue, some of our support engineers have actually driven to

2010/03/10 07:14:40 | Microsoft rolls out Internet Explorer workaround for zero-day vulnerability, as important issues are addressed on Patch Tuesday

from: SC Magazine

...as opening a malicious Excel document could lead to remote code execution. Finally, Microsoft issued security bulletin MS10-015 that caused a blue screen on systems that were recently patched. Miller said: "Microsoft researched the issue and found a rootkit...

2010/03/04 16:38:02 | Microsoft re-releases Blue Screen of Death fix

from: ZDNet UK

...to crash in February with a Blue Screen of Death. The software maker has re-written the installation package for the update, MS10-015, and will push it out automatically to users. It has written logic into the update to prevent the fix from being installed...

2010/03/03 22:08:08 | Microsoft re-releases update MS10-015

from: Ed Bott's Windows Expertise

...the problem has been resolved and Microsoft has re-released the update: [W]e have revised the installation packages for MS10-015 with new logic that prevents the security update from being installed on systems if certain abnormal conditions exist. Such conditions...

2010/03/03 21:10:46 | Microsoft Reissues Windows Kernel Patch

from: T.H.E. Journal

...consumers and enterprise customers will be available in a few weeks," Bryant said. Microsoft had originally issued the MS10-015 patch to fix a long-unaddressed bug in the Windows kernel that could allow a hacker to elevate access privileges on a hijacked system....

2010/03/02 16:00:00 | Microsoft again pushes patch linked to Windows blue screens

from: NetworkWorld

...Information Assurance Directorate, blasted Microsoft for its sluggish pace. Saying that fixing vulnerabilities can be a competitive advantage for companies, Snow cited MS10-015. "Seventeen years and not yet addressed? Give me a break," said Snow. ...

2010/03/03 03:21:15 | Microsoft Patch Aims to Stop Rootkit

from: Internet.com

...Alureon. If it's found, the user receives a notice that the operating system is "incompatible" with the patch, which is numbered MS10-015, the company said in an e-mail to InternetNews.com. "If detection logic included in Automatic Update discovers abnormal...

2010/03/02 23:27:06 | Microsoft Relaunches Troublesome Windows Update

from: PC Magazine

...the system from booting properly. And then this message: Your computer might not be compatible with Microsoft Security Update MS10-015. Proceeding with installation of the update could prevent your system from starting successfully. For additional information...

2010/03/02 20:56:27 | Microsoft again pushes patch linked to Windows blue screens

from: ComputerWorld

...by MS10-015. It denied that there was any flaw in the security update itself. "Today Microsoft resumed the distribution of MS10-015 to Windows customers through Automatic Update," Jerry Bryant, a senior manager with the Microsoft Security Response Center (MSRC),...

2010/03/02 19:52:40 | Microsoft resumes XP patch distribution; says rootkit remover coming soon

from: ZDNet

...from users systems. From a note I received from a Microsoft spokesperson: “Today Microsoft resumed the distribution of MS10-015 to Windows customers through Automatic Update. The bulletin includes added detection logic for consumer and enterprise customers...

2010/03/02 19:56:15 | Microsoft Puts Problem Update Back Online

from: PC Magazine

... And then this message: Shortly after Microsoft released MS10-015 last month, users started reporting blue-screens and rolling reboots. Microsoft pulled the update, and it quickly emerged that the problem was a certain class of malware on the systems....

2010/02/21 16:34:10 | Microsoft Windows Phone 7 Dominated This Week's Headlines

from: eWeek

...Microsoft Security Response Center. "In every investigated incident, we have not found quality issues with security update MS10-015." Alureon attempts to access a specific memory location; the issue primarily affected 32-bit machines, according to Microsoft....

2010/02/11 11:51:00 | Windows patch cripples XP with blue screen, users claim

from: ComputerWorld

Computerworld - Tuesday's security updates from Microsoft have crippled Windows XP PCs with the notorious Blue Screen of Death (BSOD), users have reported on the company's support forum. Complaints began early yesterday, and gained momentum throughout

2010/02/19 15:09:01 | Malware caused crashes during Windows updates

from: ZDNet UK

...Response Center, wrote in a blog post. "In every investigated incident, we have not found quality issues with security update MS10-015." The patch addresses a vulnerability in the 32-bit Windows kernel that could allow elevation of privilege that was disclosed...

2010/02/18 22:49:45 | Microsoft Confirms Update-Linked BSODs Required Compromised Machines

from: Slashdot

...execute and cause blue screens. Why not? DNA contains bits that will de-evolve you back into a frog or lizard or caveman. If MS10-015 was meant to protect against/fix Alureon infections, then yeah, it doesn't seem unreasonable to ask that it not hose the machine. OTOH,...

2010/02/18 22:57:39 | Malware crashed systems during Windows security updates

from: CNET

...Center, wrote in a blog post. "In every investigated incident, we have not found quality issues with security update MS10-015." The Win32/Alureon family of malware can modify DNS settings, hijack searches, and fraudulently click on ads, Microsoft said in...

2010/02/18 12:30:35 | Microsoft: Malware behind XP update BSoDs/reboots

from: ZDNet

...infected, during which the malware made assumptions as to the layout of the Windows code on the machine.  Subsequently MS10-015 was downloaded and installed, during which the location of Windows code changed.  On the next reboot the malware code crashed attempting...

2010/02/18 21:06:23 | Blue Screen Reboots After Microsoft Patch Could Mean Malware

from: PC World

...Also, problem reports have largely involved Windows XP systems. For that reason, Redmond says it will resume distributing the MS10-015 patch for 64-bit systems via Windows Update. While I'm more than willing to take Microsoft to task when they screw up, in...

2010/02/18 17:28:25 | Microsoft Confirms Blue Screen of Death Tied to Malware

from: eWeek

...during which the malware made assumptions as to the layout of the Windows code on the machine, he explained. Subsequently MS10-015 was downloaded and installed, during which the location of Windows code changed. On the next reboot, the malware code crashed attempting...

2010/02/18 14:02:40 | Microsoft readies new rootkit detection tool in light of Windows XP patching problems

from: ZDNet

...will be after Microsoft releases the Alureon rootkit-detection fix.) Users still having issues they believe may be the result of MS10-015 can obtain free support from Microsoft by going to https://consumersecuritysupport.microsoft.com or by calling 1-866-PCSafety...

2010/02/18 13:09:33 | Rootkit to blame for Windows fix resulting in blue screen

from: SC Magazine

...block access to certain websites, and redirect searches," according to a Microsoft summary. Microsoft still considers MS10-015 to be a high-priority patch. "Our guidance remains the same," Reavey said. "Customers should continue to deploy this month's security...

2010/02/18 15:05:54 | Microsoft Says Rootkit Caused Windows Blue Screens

from: PC World

...to access a specific memory location, instead of letting the operating system determine the address," explained Reavey. "MS10-015 was downloaded and installed, during which the location of Windows code changed. On the next reboot the malware code crashed attempting...

2010/02/11 17:16:38 | Windows Patch Leaves XP Users With Blue Screen of Death

from: PC World

...for netbooks, or am I essentially screwed for the time being?" asked "HimDen." Several users tentatively identified the MS10-015 update as the one which triggered the BSOD, and claimed that uninstalling that security fix -- which was labeled as KB977165 --...

2010/02/18 12:33:47 | Microsoft says rootkit caused Windows blue screens

from: ComputerWorld

...has concluded that the reboot occurs because the system is infected with malware," said Reavey. He added that the MS10-015 update was not at fault. "We have not found quality issues with security update MS10-015," Reavey maintained. Yesterday, Reavey echoed...

2010/02/18 12:25:06 | Rootkit to blame for Windows Blue Screen of Death

from: InfoWorld

...Data Loss Prevention, which covers the tools and techniques used by experienced security pros. ] He added that the MS10-015 update was not at fault. "We have not found quality issues with security update MS10-015," Reavey maintained. Yesterday, Reavey echoed...

2010/02/18 06:04:25 | The status of KB977165 and MS10-015

from: ComputerWorld

...  This seemed confirmed on February 16th when Gregg Keizer of Computerworld wrote "Microsoft has not yet restored the MS10-015 patch to Windows Update, so users can safely download and install all remaining updates issued last week."   Turns out, it wasn't...

2010/02/17 14:50:43 | Microsoft security patch flaw plugged by hackers

from: Inquirer

...on its tech blog. The Vole's blog post reads, "In our continuing investigation in to the restart Issues related to MS10-015 that a limited number of customers are experiencing, we have determined that malware on the system can cause the behavior. We are not...

2010/02/17 17:53:28 | Has the problematic Windows patch been pulled or not?

from: ComputerWorld

...posting has not been updated in the six days since it was written. The patch in question is known as MS10-015 and as KB977165, depending on the context. "Automatic Updates for MS10-015 will remain disabled until our investigation into the restart issues...

2010/02/17 17:01:32 | Microsoft Update Inadvertently Finds Compromised Computers

from: IEEE Spectrum

...the restart issues is complete." Maybe Microsoft would be doing a lot of people a favor by announcing that it was now releasing MS10-015 along with a message stating that if you end up with the BSOD, you are probably infected, along with what to do next. The...

2010/02/16 16:00:00 | Hackers update rootkit causing Windows blue screens

from: NetworkWorld

...to Windows Update, so users can safely download and install all remaining updates issued last week. "Automatic Updates for MS10-015 will remain disabled until our investigation into the restart issues is complete," Jerry Bryant, a senior manager with the Microsoft...

2010/02/16 23:12:35 | Rootkit Authors Issue Patch For Critical Bug

from: PC Magazine

...caused the BSOD was due to the rootkit hard-coding the address of a particular Windows routine, and this address was moved by MS10-015. The rootkit authors had a fix out before too long, but that wasn't enough to save large numbers of users who couldn't boot...

2010/02/16 22:52:03 | Hackers "fix" XP BSoD rootkit

from: ZDNet

...number of the users affected by this BSOD was infected by TDL3/TDSS rootkit. More exactly, TDL3 rootkit looks incompatible with MS10-015 update. This is the cause of the BSOD. Problem resides in the lazyness of rootkit writers when writing the driver infection...

2010/02/16 22:04:35 | Hackers update rootkit causing Windows blue screens

from: ComputerWorld

...screen," said Fossi. Schouwenberg noted that rootkit-infected machines running any flavor of Windows will crash when the MS10-015 update is applied. "This affects every version of Windows," he said, including Vista and Windows 7. "The reason why it's been...

2010/02/15 12:55:17 | Malware Cause For Blue Screens After Recent Windows Update

from: GHacks Technology News

...addressed the issue shortly after reports began to appear and revealed that the issues were linked to the patch MS10-015. The company did however mention at this time that it was not clear yet if the patch was the cause for the problems. While that has not...

2010/02/15 17:11:02 | Infection may have triggered Blue Screens of Death

from: ZDNet UK

...on Windows systems, according to the company. "In our continuing investigation into the restart issues related to MS10-015 that a limited number of customers are experiencing, we have determined that malware on the system can cause the behaviour," said a Microsoft...

2010/02/15 09:53:59 | Rootkit blamed for Blue Screen patch update snafu

from: The Register

...our continuing investigation into the restart issues related to MS10-015 that a limited number of customers are experiencing, we have determined that malware on the system can cause the behavior. We are not yet ruling out other potential causes at this time...

2010/02/13 22:04:41 | Some XP Users Get BSOD After Patch Tuesday, Malware Blamed

from: [H]ard | OCP

Because TDSS uses crafty techniques to hide itself on the operating system, many antivirus programs have a hard time detecting it, said Roel Schouwenberg, a Kaspersky antivirus researcher. "The more I look into it, the more plausible it becomes that

2010/02/13 05:50:12 | Windows XP patch fiasco gets even crazier, Microsoft now scrambling for solutions

from: Engadget

...giant's following quote: Rock, meet hard place. "In our continuing investigation in to the restart issues related to MS10-015 that a limited number of customers are experiencing, we have determined that malware on the system can cause the behavior. We...

2010/02/12 23:13:42 | Microsoft Affirms BSOD, Halts Windows Patch

from: RedmondMag.com

...malware though." Because of the snafu and pending investigation, Microsoft has temporarily pulled security bulletin MS10-015 from automatic release through Windows Update. However, the patch still remains on Microsoft update sites for administrators to download...

2010/02/12 22:18:19 | Microsoft says malware causing blue screen crashes

from: ComputerWorld

...researcher. "The more I look into it, the more plausible it becomes that this is indeed the (main) issue behind the BSOD. MS10-015 is a kernel update with atapi.sys containing the extremely advanced TDSS kernel rootkit," he said via instant message. "Microsoft...

2010/02/13 00:36:45 | Microsoft’s latest patch gives XP users the gift of BSOD

from: Gadgetell

...and unusable systems. The company’s support forums have been flooded with complaints from angry users since the release of MS10-015. “I updated 11 Windows XP updates today and restarted my PC like it asked me to,” said a user identified as “tansenroy” who...

2010/02/12 19:42:29 | Malware might be cause of Restart Issues MS10-015

from: Bink.nu

... One of the key components when investigating issues like this are obtaining memory dumps from computers experiencing the problem. In order to get the information we need to fully analyze the issue, some of our support engineers have actually driven to cus...

2010/02/12 15:11:24 | Microsoft removes patch from Windows Update

from: SC Magazine

Microsoft has stopped offering one of its recent patches, MS10-015, through Windows Update because a "limited number of users" are having difficulty restarting their computers after installing the fix, Jerry Bryant, senior security communications

2010/02/09 16:00:00 | Microsoft delivers huge Windows security update

from: NetworkWorld

For the second time in the last four months, Microsoft today shipped a record 13 security updates that patched dozens of vulnerabilities in Windows. The 26 flaws fixed today were off the record of 34 set in October 2009 when Microsoft last issued 13

2010/02/12 14:14:27 | The Latest Security Patch from Microsoft Cripples Windows XP with Blue Screen Of Death

from: Simple Thoughts

...of the netbooks lack any optical drive. So, they can not be booted from CD or DVD. Many users tentatively found that the MS10-015 update is the one  which triggered the BSOD, and claimed that uninstalling that security fix which was labeled as KB977165 , brings...

2010/02/12 19:12:24 | Microsoft Pulls Patch that Causes Blue Screen of Death

from: PC World

...of the now-missing MS10-015 with a automated workaround that disables the vulnerable NT Virtual DOS Mode (NTVDM) subsystem. MS10-015 quashed a pair of 17-year-old kernel bugs in all 32-bit versions of Windows. The vulnerability went public three weeks ago...

2010/02/12 12:19:01 | Microsoft stops serving Window patch blamed for blue screens

from: ComputerWorld

...on the update problem. Not surprisingly, rumors began circulating about possible causes of the apparent conflict between the MS10-015 update and some, though certainly not all, Windows XP machines. One making the rounds ended up on the support thread: "Is...

2010/02/12 11:04:29 | Microsoft Addresses Windows Restart Issues

from: GHacks Technology News

...the Senior Security Communications Manager, states that Microsoft has not yet ” confirmed that the issue is specific to MS10-015″ as it could also be an “interoperability problem with another component or third-party software”. Microsoft has pulled the security...

2010/02/12 11:22:49 | Windows update causes blue screen of death

from: Inquirer

...issue occurs after installing update MS10-015 (KB977165). However the Vole refuses to confirm that the issue is specific to MS10-015 or if it is an interoperability problem with another component or third-party software. "Our teams are working to resolve this...

2010/02/12 10:45:37 | Microsoft security patch brings BSOD misery for XP users

from: PC Pro

...the cause of the complaints, users have narrowed the problem to update KB977165, described by Microsoft as "MS10-015: Vulnerabilities in Windows kernel could allow elevation of privilege". The patch was intended to address a 17-year-old kernel bug present...

2010/02/12 10:04:52 | NEWS: XP patch brings blue screen misery

from: Pocket Lint

...optical drive, however - which will affect a growing number of netbook users. Other users have said that uninstalling patch MS10-015, labelled as KB977165, brought their computer back to life. The patch fixes a kernel bug that allows an attack on a Windows...

2010/02/12 10:18:56 | Restart issues after installing MS10-015

from: Bink.nu

...address this issue, customers who choose not to install the update can implement the workaround outlined in the bulletin. CVE-2010-0232 was publicly disclosed and we previously issued Security Advisory 979682 in response. Customers can disable the NTVDM subsystem...

2010/02/11 16:51:10 | Microsoft looks into patch installation problem

from: SC Magazine

...the so-called blue screen of death when they attempt to restart. The potentially broken patch reportedly is bulletin MS10-015, which repairs privilege-escalation vulnerabilities in the Windows kernel. — DK This material may not be published, broadcast, rewritten...

2010/02/12 01:57:25 | Microsoft Investigating Windows Blue Screen of Death Reports

from: eWeek

...to Microsoft, the issue appears to be related to MS10-015, but it has not been determined if it is specific to MS10-015 or if it is an interoperability problem with another component or third-party software. The bulletin addresses two Windows Kernel privilege...

2010/02/11 16:27:49 | Windows patch cripples XP with blue screen, users claim

from: NetworkWorld

Tuesday's security updates from Microsoft have crippled Windows XP PCs with the notorious Blue Screen of Death (BSOD), users have reported on the company's support forum. Complaints began early yesterday, and gained momentum throughout the day. "I

2010/02/11 16:48:51 | MS update gives some XP boxes the Blue Screen

from: The Register

...from Microsoft can cause Windows XP machines to crash with the infamous blue screen of death. Updating systems with the MS10-015 bulletin, which addresses "important" vulnerabilities in Windows Kernel, can cause machines to lock up when restarted before falling...

2010/02/11 12:29:52 | Windows patch cripples XP with blue screen, users claim

from: ComputerWorld

...and claimed that uninstalling that security fix -- which was labeled as KB977165 -- returned their PC to working condition. MS10-015, one of 13 security updates Microsoft issued Tuesday, patched a 17-year-old kernel bug in all 32-bit versions of Windows. The...

2010/02/10 14:48:27 | Microsoft Security Updates February 2010

from: GHacks Technology News

...all supported editions of Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008Microsoft Security Bulletin MS10-015 – Important – Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165) – his security update resolves...

2010/02/09 23:52:00 | Microsoft Plugs 26 Vulnerabilities With 13 Patches In Record Update

from: Channel Web

...the vulnerabilities, proof-of-concept exploit code exists for two vulnerabilities addressed by Microsoft bulletin MS10-015, addressing errors designated as "important" in the Windows Kernel that could enable elevation of privileges if an attacker logged onto...

2010/02/09 22:16:38 | Critical Windows Fixes For DirectShow, Network-based Attacks

from: PC World

...as top priority by the MSRC post because of publicly available proof-of-concept attack code. The vulnerability fixed by MS10-015 allows a logged-in user to run a "specially crafted application" to gain additional privileges on a system. Such privilege escalation...

2010/02/09 20:12:29 | Microsoft delivers huge Windows security update

from: ComputerWorld

...2008's Hyper-V virtualization software; the Windows kernel; and other bits and pieces of Windows. The kernel update, MS10-015, patched the 17-year-old bug in all 32-bit versions of Windows that went public Jan. 19 when a Google engineer disclosed the vulnerability...

2010/02/10 06:50:06 | Microsoft releases first heavy batch of bulletins on the second Patch Tuesday of 2010

from: SC Magazine

...earn this vulnerability close intense scrutiny by the hacker community. Microsoft also recommends prioritising MS10-008 and MS10-015.” The MS10-013 patch addresses a vulnerability in Microsoft DirectShow where a specially crafted AVI file leads to remote execution...

2010/02/09 22:03:12 | Microsoft Fixes Windows Security Vulnerabilities in Patch Tuesday Update

from: eWeek

...Server 2003. MS10-008 is a remote code execution vulnerability in the Microsoft Data Analyzer ActiveX Control, while MS10-015 fixes two privilege escalation bugs in the Windows Kernel. Though the Windows Kernel bulletin is rated important and not critical, it...

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use