Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution


Go Back   Computer Help Articles > Windows XP General
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 02:29 AM
PA Bear
 
Posts: n/a
Default Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution

[Followup-to set for microsoft.public.security]

The Advisory as updated on 30 Dec-05 now states that Software DEP does *not*
block the exploit.

http://www.microsoft.com/technet/sec...ry/912840.mspx

<QP>
I have DEP enabled on my system, does this help mitigate the
vulnerability?

Software based DEP does not mitigate the vulnerability. However,
Hardware based DEP may work when enabled: please consult with your
hardware manufacturer for more information on how to enable this and
whether it can provide mitigation.
</QP>
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE, Shell/User, Security), Aumha.org VSOP, DTS-L.org

PA Bear wrote:
> In fact, there are various recent posts elsewhere stating that DEP blocked
> the exploit. YMMV.
>
> jacecarter@gmail.com wrote:
> > Data Execution Prevention?
> > What happened to DEP in XP SP2?
> >
> > If this is a buffer overflow exploit, why then isn't DEP in XP SP2
> > shutting down the malicious code before it can run?
> >
> > I would think that an image file would be marked as "data" in memory,
> > not as an executable image, although WMF might be different than say a
> > jpg or bmp, does anyone know for sure?
> >
> > I keep my DEP setting on "Turn on DEP for all programs and services
> > except those I select"
> >
> > http://www.microsoft.com/technet/sec.../depcnfxp.mspx
> >
> > "Microsoft Windows XP Service Pack 2 (SP2) helps protect your computer
> > against the insertion of malicious code into areas of computer memory
> > reserved for non-executable code by implementing a set of hardware and
> > software-enforced technologies called Data Execution Prevention (DEP).
> > Hardware-enforced DEP is a feature of certain processors that prevents
> > the execution of code in memory regions that are marked as data
> > storage. This feature is also known as No-Execute and Execution
> > Protection. Windows XP SP2 also includes software-enforced DEP that is
> > designed to reduce exploits of exception handling mechanisms in
> > Windows.
> >
> > Unlike an antivirus program, hardware and software-enforced DEP
> > technologies are not designed to prevent harmful programs from being
> > installed on your computer. Instead, they monitor your installed
> > programs to help determine if they are using system memory safely. To
> > monitor your programs, hardware-enforced DEP tracks memory locations
> > declared as "non-executable". To help prevent malicious code, when
> > memory is declared "non-executable" and a program tries to execute code
> > from the memory, Windows will close that program. This occurs whether
> > the code is malicious or not."


Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
MS Security Bulletin MS06-001: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (912919) PA Bear Internet Explorer 6 0 01-05-2006 11:15 PM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Re Stephen Howe Windows XP General 8 01-05-2006 02:28 AM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution Kerry Brown Windows XP General 1 01-05-2006 02:25 AM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Re PA Bear Windows XP General 0 01-05-2006 02:25 AM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphic Tom [Pepper] Willett Windows XP General 0 01-05-2006 02:24 AM


All times are GMT. The time now is 01:51 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution