CVE-2012-0001
published 2012-01-10CVE-2012-0001: The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does…
PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.55%
95.0th percentile
The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
cisa7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9563-jv23-5rh9: The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP
ghsa_unreviewed·2022-05-04
CVE-2012-0001 [HIGH] GHSA-9563-jv23-5rh9: The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP
The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
CISA
Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-0001 [HIGH] Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Vulnerability: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Affected: Microsoft Graphics Device Interface (GDI)
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0001
Remediation Due Date: 2022-03-24
No detection rules found.
Exploit-DB
VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
exploitdb·2012-10-11
CVE-2012-5470 VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
---
#!/usr/bin/perl
# VLC Player 2.0.3
# Vendor URI: http://www.videolan.org/vlc/
# Vendor Description:
# VLC is a free and open source cross-platform multimedia player
# and framework that plays most multimedia files as well as DVD,
# Audio CD, VCD, and various streaming protocols.
# Debug Info:
# Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
# Copyright (c) Microsoft Corporation. All rights reserved.
#
# CommandLine: "C:\Program Files\VideoLAN\VLC\vlc.exe" C:\research\VLC\crafted.png
# Symbol search path is: *** Invalid ***
# ****************************************************************************
# * Symbol loading may be unreliable without a symbol search path. *
# * Use .symfix to have the debugger choose
Exploit-DB
JPEGsnoop 1.5.2 - WriteAV Crash (PoC)
exploitdb·2012-10-04
CVE-2012-6307 JPEGsnoop 1.5.2 - WriteAV Crash (PoC)
JPEGsnoop 1.5.2 - WriteAV Crash (PoC)
---
#!/usr/bin/perl
# JPEGsnoop 1.5.2
# Vendor URI: http://sourceforge.net/projects/jpegsnoop/
# Vendor Description:
# JPEGsnoop is a detailed JPEG image decoder and analysis tool.
# It reports all image metadata and can even help identify if an image has been edited.
# Debug info:
# Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
# Copyright (c) Microsoft Corporation. All rights reserved.
#
# CommandLine: C:\JPEGsnoop.exe C:\research\JPEGsnoop\crafted.jpeg
# Symbol search path is: *** Invalid ***
# ****************************************************************************
# * Symbol loading may be unreliable without a symbol search path. *
# * Use .symfix to have the debugger choose a symbol path. *
# * After setting your symbol path,
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00016.htmlhttp://secunia.com/advisories/47356http://www.securityfocus.com/bid/51296http://www.securitytracker.com/id?1026493http://www.us-cert.gov/cas/techalerts/TA12-010A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-001https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14758http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00016.htmlhttp://secunia.com/advisories/47356http://www.securityfocus.com/bid/51296http://www.securitytracker.com/id?1026493http://www.us-cert.gov/cas/techalerts/TA12-010A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-001https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14758
2012-01-10
Published