Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Microsoft Windows win32k.sys Driver 'CreateDIBPalette()' BOF Vulnerability

Information

Severity

Severity

High

Family

Family

Windows

CVSSv2 Base

CVSSv2 Base

7.2

CVSSv2 Vector

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

13 years ago

Modified

Modified

5 years ago

Summary

This host is prone to buffer ovreflow vulnerability.

Insight

Insight

The flaw is due to a buffer overflow error in the 'CreateDIBPalette()' function within the kernel-mode device driver 'Win32k.sys', when using the 'biClrUsed' member value of a 'BITMAPINFOHEADER' structure as a counter while retrieving Bitmap data from the clipboard.

Affected Software

Affected Software

Microsoft Windows 7 Microsoft Windows XP SP3 and prior. Microsoft Windows Vista SP 2 and prior. Microsoft Windows Server 2008 SP 2 and prior. Microsoft Windows Server 2003 SP 2 and prior.

Solution

Solution

Apply the latest updates

Common Vulnerabilities and Exposures (CVE)