Vulnerabilities / Threats
8/14/2012
04:15 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Palo Alto Networks Discovers Critical Vulnerabilities In Windows Print Spooler And Remote Administration Protocol

Vulnerabilities allow attackers to remotely execute code and take control of systems

SANTA CLARA, Calif., Aug. 14, 2012 /PRNewswire/ -- Palo Alto Networks(TM) (NYSE: PANW), the network security company, today announced that its Threat Research Team was credited with identifying two critical vulnerabilities and one important vulnerability in the Remote Administration Protocol (RAP) and one critical vulnerability in the Windows Print Spooler service.

The discovered critical vulnerability in the Windows Print Spooler - CVE-2012-1851 - is a remote code execution vulnerability that could allow an attacker to run arbitrary code on a user's system with system privileges and take control of the affected system. This vulnerability is in Windows XP and Windows Server 2003 machines. This vulnerability will also result in a Denial of Service state in Windows Vista, Windows 7 and Windows Server 2008.

The discovered critical vulnerabilities in the Remote Administration Protocol - CVE-2012-1852 and CVE-2012-1853 - are heap and stack overflow vulnerabilities that could allow an attacker to remotely take control of the affected system. Both vulnerabilities are in Windows XP.

The discovered important Remote Administration Protocol vulnerability - CVE-2012-1850 - could allow an attacker who successfully exploited this vulnerability to cause a target application to stop responding. CVE-2012-1850 is in multiple versions of Windows and Windows Server.

The Palo Alto Networks Threat Research Team

The Palo Alto Networks Threat Research Team is active in the research community, aggressively pursuing both new vulnerability research and alleviation of all types of threats. The team has leveraged its expertise to uncover a string of critical and important vulnerabilities and has then worked with Microsoft to make sure users are protected.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web