// For flags

CVE-2006-6696

Microsoft Windows - 'MessageBox' Memory Corruption Local Denial of Service

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.

Vulnerabilidad de liberación de memoria doble en Microsoft Windows 2000, XP, 2003, y Vista, permite a usuarios locales obtener privilegios llamando a la función MessageBox con un mensaje MB_SERVICE_NOTIFICATION con datos manipulados, lo cual envía un mensaje HardError al proceso Subsistema de servidor en ejecución de Cliente/Servidor (CSSRSS), que no es gestionado apropiadamente cuando se invocan las funciones UserHardError y GetHardErrorText en WINSRV.DLL.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-12-20 First Exploit
  • 2006-12-21 CVE Reserved
  • 2006-12-22 CVE Published
  • 2024-02-17 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (25)
URL Tag Source
http://blogs.technet.com/msrc/archive/2006/12/22/new-report-of-a-windows-vulnerability.aspx X_refsource_confirm
http://groups.google.ca/group/microsoft.public.win32.programmer.kernel/browse_thread/thread/c5946bf40f227058/7bd7b5d66a4e5aff X_refsource_misc
http://isc.sans.org/diary.php?n&storyid=1965 X_refsource_misc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051394.html Mailing List
http://research.eeye.com/html/alerts/zeroday/20061215.html X_refsource_misc
http://securitytracker.com/id?1017433 Vdb Entry
http://www.determina.com/security.research/vulnerabilities/csrss-harderror.html X_refsource_misc
http://www.kuban.ru/forum_new/forum2/files/19124.html X_refsource_misc
http://www.security.nnov.ru/Gnews944.html X_refsource_misc
http://www.security.nnov.ru/files/messagebox.c X_refsource_misc
http://www.securityfocus.com/archive/1/455061/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/455088/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/455104/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/455158/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/455546/100/0/threaded Mailing List
http://www.securityfocus.com/bid/21688 Vdb Entry
http://www.securityfocus.com/bid/23324 Vdb Entry
http://www.vupen.com/english/advisories/2006/5120 Vdb Entry
http://www.vupen.com/english/advisories/2007/1325 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1816 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
*-
Affected
Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
*sp1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
*sp2
Affected
Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
*sp3
Affected
Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
*sp4
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
datacenter_edition
Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition"
-
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
datacenter_edition
Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
datacenter_edition
Search vendor "Microsoft" for product "Windows 2003 Server" and version "datacenter_edition"
sp1_beta_1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
enterprise_edition
Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
enterprise_edition
Search vendor "Microsoft" for product "Windows 2003 Server" and version "enterprise_edition"
sp1_beta_1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
sp1
Search vendor "Microsoft" for product "Windows 2003 Server" and version "sp1"
enterprise
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
standard
Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard"
-
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
standard
Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
standard
Search vendor "Microsoft" for product "Windows 2003 Server" and version "standard"
sp1_beta_1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
web
Search vendor "Microsoft" for product "Windows 2003 Server" and version "web"
-
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
web
Search vendor "Microsoft" for product "Windows 2003 Server" and version "web"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Windows 2003 Server
Search vendor "Microsoft" for product "Windows 2003 Server"
web
Search vendor "Microsoft" for product "Windows 2003 Server" and version "web"
sp1_beta_1
Affected
Microsoft
Search vendor "Microsoft"
Windows Vista
Search vendor "Microsoft" for product "Windows Vista"
*december_ctp
Affected
Microsoft
Search vendor "Microsoft"
Windows Vista
Search vendor "Microsoft" for product "Windows Vista"
*beta
Affected
Microsoft
Search vendor "Microsoft"
Windows Vista
Search vendor "Microsoft" for product "Windows Vista"
*beta1
Affected
Microsoft
Search vendor "Microsoft"
Windows Vista
Search vendor "Microsoft" for product "Windows Vista"
*beta2
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*home
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*media_center
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*gold, professional
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*sp1, home
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*sp1, media_center
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*sp2, home
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*sp2, media_center
Affected
Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
*sp2, tablet_pc
Affected