MS KB2927432: Visual Studio Update 2 for Debug Interface Access SDK

medium Nessus Plugin ID 74154

Synopsis

An SDK library on the remote Windows host is affected by a memory corruption vulnerability.

Description

The version of the Microsoft Debug Interface Access Library on the remote host is affected by a memory corruption vulnerability related to parsing PDB files. An attacker could exploit this issue by tricking a user into loading a malicious file. This could allow an attacker to execute arbitrary code or cause a denial of service condition.

This issue is believed to be fixed in Visual Studio 2013 Update 2.
Please see Microsoft knowledge base article 2927432 for more details.

Solution

Upgrade to Microsoft Visual Studio 2013 Update 2. See KB2927432.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-14-129/

http://www.nessus.org/u?f1e00801

Plugin Details

Severity: Medium

ID: 74154

File Name: smb_kb2927432.nasl

Version: 1.7

Type: local

Agent: windows

Family: Windows

Published: 5/23/2014

Updated: 3/27/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2014-3802

CVSS v3

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 5.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:visual_studio

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 5/12/2014

Vulnerability Publication Date: 5/14/2014

Reference Information

CVE: CVE-2014-3802

BID: 67398

MSKB: 2927432