Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Windows Kernel Exception Handler Vulnerability (MS10-015)

Subscribe

Check Point Reference: CPAI-2010-104
Date Published:
Severity:
Source: Microsoft Security Bulletin MS10-015
Industry Reference(s):

CVE-2010-0232

Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows 7
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Server 2008
Microsoft Windows Storage Server 2003
Microsoft Windows Vista
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional
Vulnerability Description
An elevation of privilege vulnerability exists in the Windows Kernel due to the way the kernel handles certain exceptions. The Windows Kernel is the core of the operating system, providing system level services such as device management and memory management. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
Update/Patch Available
Microsoft has provided a patch:
Microsoft Security Bulletin MS10-015 
Vulnerability Details
The Windows kernel does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (NTVDM) subsystem. The Windows Virtual DOS Machine (NTVDM) subsystem is a protected environment subsystem that emulates MS-DOS and 16-bit Windows within Windows NT-based operating systems.

Protection Overview

IPS-1 will detect and block he transfer of windows PE files over HTTP, SMTP, FTP, TFTP and IRC.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?

1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles > and select the Microsoft .NET CLI PE Header Memory Corruption protection group.
3. Click Microsoft Windows Kernel Exception Handler Vulnerability (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?

Upon attack, the following entries will be logged:

Alert Name: Microsoft PE Executable Source
Description: Microsoft Windows Kernel Exception Handler Vulnerability