TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
(MS08-075) Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349)
Vulnerability Identifier: CVE-2008-4268; CVE-2008-4269
Discovery Date: Dec 9, 2008
Risk: Critical
Affected Software:
  • Windows Server 2008 for 32-bit Systems
  • Windows Server 2008 for Itanium-based Systems
  • Windows Server 2008 for x64-based Systems
  • Windows Vista
  • Windows Vista Service Pack 1
  • Windows Vista x64 Edition
  • Windows Vista x64 Edition Service Pack 1
Description:

This security update resolves two privately reported vulnerabilities in Windows Search. These vulnerabilities could allow remote code execution if a user opens and saves a specially crafted saved-search file within Windows Explorer or if a user clicks a specially crafted search URL.

A remote malicious user who successfully exploits these vulnerabilities could take complete control of an affected system. The said malicious user could then install programs; view, change, or delete data; or create new accounts with full user rights.

Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


Patch Information:

Patches for this vulnerability can be downloaded on this Microsoft Web page.
 
Search for another Security Advisory
Keyword: