Color Control Panel vulnerability could allow remote code execution
Report ID: MS201202005
Date Published: 15 February 2012
Criticality: Important
Compromise Type: remote-code-execution
Compromise From: remote
Affected Product/Component:
Windows Server 2008
Windows Server 2008 R2
Summary
A vulnerability involving Color Control Panel in Microsoft Server 2008 and Microsoft Server 2008 R2 could allow an attacker to execute code and take control of an affected system.
Detailed Description
Microsoft has released a security update to address a vulnerability affecting Microsoft Server 2008 and Microsoft Server 2008 R2. The vulnerability existed when the path used for loading external files is improperly restricted, and could be exploited by an attacker to execute code in the context of a logged-on user.
This vulnerability issue has been fixed by correcting the way Color Control Panel loads external libraries. Users are recommended to install the latest update to protect their system from potential exploit.
CVE Reference
CVE-2010-5082
Solution
Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-012)




