Skip to content

Windows systems under attack using zero-day vulnerability

Windows logoMicrosoft® Windows® XP and Windows Server® 2003 systems are being attacked through CVE-2007-5587, a buffer overflow vulnerability in the Macrovision secdrv.sys driver.

The driver handles configuration parameters incorrectly. This allows an attacker with local access to a system to overwrite arbitrary memory locations, gaining SYSTEM privileges.

This vulnerability was first reported in mid-October 2007. No workarounds are known, but Microsoft (Nasdaq: MSFT) plans to provide a security update through the monthly release process.

External links:

Do you have any experiences or other news regarding this vulnerability? Please post your comments!

Post a Comment

Your email is never published nor shared. Required fields are marked *
*
*