First published: Wed Apr 13 2011(Updated: )
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp3 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows 7 | ||
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Avaya Integrated Management | ||
Avaya Meeting Exchange | >=5.0.0<=5.2.0 | |
Avaya Aura Conferencing Standard Edition | =6.0.0 | |
Avaya Communication Server 1000 Telephony Manager | >=3.0.0<=4.0.0 | |
Avaya CallPilot | >=4.0.x<=5.0.x | |
Avaya Messaging Application Server | >=4.0.x<=5.2.x | |
Avaya Web Messenger | ||
Avaya Visual Vector Client | ||
Avaya Unified Communication Center | ||
Avaya Speech Access | ||
Avaya Outbound Contact Management | ||
Avaya Operational Analyst | ||
Avaya Network Reporting | ||
Avaya IP Softphone | ||
Avaya IP Agent | ||
Avaya Interaction Center | ||
Avaya Enterprise Manager | ||
Avaya Customer Interaction Express | ||
Avaya Contact Center Express | ||
Avaya Computer Telephony | ||
Avaya CallVisor ASAI LAN | ||
Avaya Call Management System Supervisor | ||
Avaya Basic Call Management System Reporting Desktop | ||
Avaya Agent Access | ||
Avaya OctelAccess Server | ||
Avaya Unified Messenger | ||
Avaya VPNmanager Console | ||
Avaya Octel Designer | ||
Avaya Visual Messenger |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1229 has a critical severity rating as it allows local users to gain elevated privileges through a crafted application.
To mitigate CVE-2011-1229, ensure that all affected Microsoft Windows versions are updated to the latest security patches.
CVE-2011-1229 affects Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008, and Windows 7.
CVE-2011-1229 is a local privilege escalation vulnerability in the win32k.sys driver.
No, CVE-2011-1229 requires local access to exploit the vulnerability, making it less prone to remote attacks.